{"_id":"json-server-auth","_rev":"10-9e14f6db8464406eed721d37961577b5","name":"json-server-auth","dist-tags":{"latest":"2.1.0","next":"2.0.3-b"},"versions":{"1.0.0":{"name":"json-server-auth","description":"Authentication middleware for json-server","version":"1.0.0","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist/bin.js"},"engines":{"node":">=8.10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest --watch --verbose false"},"dependencies":{"bcryptjs":"^2.4.3","body-parser":"^1.18.3","express":"^4.16.4","json-server":"^0.14.0","jsonwebtoken":"^8.4.0","yargs":"^12.0.5"},"peerDependencies":{},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/express":"^4.16.0","@types/jest":"^23.3.10","@types/json-server":"^0.14.0","@types/jsonwebtoken":"^8.3.0","@types/supertest":"^2.0.7","@types/yargs":"^12.0.1","jest":"^23.6.0","rimraf":"^2.6.2","supertest":"^3.3.0","ts-jest":"^23.10.5","ts-node-dev":"^1.0.0-pre.31","tslint":"^5.11.0","tslint-config-prettier":"^1.17.0","typescript":"^3.2.1","typescript-tslint-plugin":"^0.1.2"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@1.0.0","dist":{"shasum":"855eb9189cb771d18d70588a27df0fac59ca6e35","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-1.0.0.tgz","integrity":"sha512-nffc0K82B3o+yzdoR8BvZxTKjCJwihhL2Ihw/ZTViXCOMh0z7/KU3x6AwQK2r/Za6R716Fp+i+5gtK3o+manHA==","fileCount":20,"unpackedSize":21008,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJcFuGVCRA9TVsSAnZWagAAo/EP/R4M/QMRlBYiJZH+7dMH\n5pQU/JYu+6fvxtskMlexr9DbsgazHZA8xa1hVM+z7aWArxycSbTy8ZbvaMcs\nEw9eqtPbl7nRinBUw8nlv/iM5K9+uEn1PgJAAKycJkn0xZMub/SfeOZwjPom\nkITBuHHiTDdhLN9H0VhWxwlTuuKFKAHD/qwUJlfurQRGfkfmqe69qSkXUzVH\nfeTybK3zLcXbF2fbxAV9ttlwFA1Lg1WNTmcd0V9By7MS8PrIlVLBj/j5mdnK\npoDNGC0zpx3DDxWMfGyQzkXHfOVYFfWwJyvORwFd41GukyexPWmCMHXtODuY\nnsU9vE5hsV/lPB36hR6nkMCvfvA7ZP+84MhGJd+TuvraLd15uIjSczTkqH8v\n/x5CnsYJ65svLYUjkPVqcMbvoXpmUwCQKUt9ocWLmXdV3iCI6SeF8a3hyofs\nrCU6ktyiAzlCD+Cz8wlCGEW0W7dtL7j7xDkRKmUbqDF0ASn93CYoE3m0zrEF\nWbGaCgFxPW+LO7u8+LCeX4tHWLKTM8u0DbEThEzJOlYwqbTGEELC/8SFN4fV\n7Ljjx8RszCfN5Sv6ui/ww/nFbU1wJOVzlbOlGJOi4ldeXdPreoPIDHVKv4Cw\nrRBGq8fnFhLQPBdBull8aoT3iQK0qNWRqXD4DK5f6sjQUJxnZqQK7bD6graM\nbN3b\r\n=wIJw\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCVbkJQMvC1ZBmrCLE//Xd4ALZdh4AJNRPmJmBV3dRVcQIhAPWNq3zJ3iAcZ/Rou5OBIGaA134i4T9uzelav0g6K3ls"}]},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_1.0.0_1545003412639_0.43595829936208164"},"_hasShrinkwrap":false},"1.1.0":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"1.1.0","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist/bin.js"},"engines":{"node":">=8.10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest --watch --verbose false"},"dependencies":{"bcryptjs":"^2.4.3","body-parser":"^1.18.3","express":"^4.16.4","json-server":"^0.14.0","jsonwebtoken":"^8.4.0","yargs":"^12.0.5"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/express":"^4.16.0","@types/jest":"^23.3.10","@types/json-server":"^0.14.0","@types/jsonwebtoken":"^8.3.0","@types/supertest":"^2.0.7","@types/yargs":"^12.0.1","jest":"^23.6.0","rimraf":"^2.6.2","supertest":"^3.3.0","ts-jest":"^23.10.5","ts-node-dev":"^1.0.0-pre.31","tslint":"^5.11.0","tslint-config-prettier":"^1.17.0","typescript":"^3.2.1","typescript-tslint-plugin":"^0.1.2"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@1.1.0","dist":{"shasum":"3dc5c2034d1c939c80fb72bcb8b4524afa1faee8","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-1.1.0.tgz","integrity":"sha512-1oiZB+UQCO3+y9IsQ0mvoMYl2qeYPRwY7Eibv5NQi2MLmF8Esvhho9VoumbJ0/ZBRx15wRfIvNOsMUG9N5UJZg==","fileCount":20,"unpackedSize":30374,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJcIC0/CRA9TVsSAnZWagAAZCkP/2z4PrV8kXf9iq2pw2Xt\naj+RBYeI0qkw6zOl5shFOafAbg6u40TSgU1F6Tca8uMvWGa77biSQaVFdHin\nKAG5BllfJXBdax6DBbNh8DYA1VZa/5sKCnbt0M1spmtr0btjTvplurM38Olc\noEhZQWYZYm4fQJ9+6JpTW6S+Uux15YRS8swFOBxrJa9mLmE+ZwcKxrcx81UX\nBkjWkFhDtmEhMl3IV8gCRu5nZTg4SEe0cXrdsid820DQlgc+YtIHAdxNE/Rz\nQTXOxJE7ok1PA/M6U9YpZA7Xwb0i/vDtq6/t4xAH066jJZhBFCjdyRWvGfNH\nJnEF0cd6dI0kj1T6xq+bcNVBkIY0FR2zU6X85YwIlQRyMHym/6DXX7Y5heqE\nMCiEVb2sLUokhPCAMNH778XderG6cpC3BHJkw9FgE94pVHFX0dIpNa4YMlKT\nylLFAFEJLJaL8ALdpIblD8SEGBkUkdgKTd4ac8jtFORIB/cQFIsrFaBc9bED\ndxSQsrFLtUqivC8YrgDKFVY2EBsAOLmpd5njNrEMg4WqVDeWdg/c5JS43kT3\n2tnS+f/+5+Bz2cD8DXUco4gIMTEXPP+LWXERlDD/aeeUf78TVRyOuChDVJNX\nSb8oMkGFefMn1yvVUI6MjWldDJJRkKrzLBd6wnbY0XzGNtRNYKH6a2nLTHqI\n9B8T\r\n=apDi\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCbwusi8kxor9cYQWsdRPU15eYRVQl1sF0DMBd01lAb9wIhALXkqLXc0pwJlj7pkqAERFgJKLUFNQOqfSyI1pbmW16f"}]},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_1.1.0_1545612606343_0.7211056702409548"},"_hasShrinkwrap":false},"1.2.0":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"1.2.0","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist/bin.js"},"engines":{"node":">=8.10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest","test:watch":"jest --watch --verbose false"},"dependencies":{"bcryptjs":"^2.4.3","body-parser":"^1.19.0","express":"^4.16.4","json-server":"^0.14.2","jsonwebtoken":"^8.5.1","yargs":"^13.2.2"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/express":"^4.16.1","@types/jest":"^24.0.12","@types/json-server":"^0.14.0","@types/jsonwebtoken":"^8.3.2","@types/supertest":"^2.0.7","@types/yargs":"^13.0.0","jest":"^24.8.0","rimraf":"^2.6.3","supertest":"^4.0.2","tree-kill":"^1.2.1","ts-jest":"^24.0.2","ts-node-dev":"^1.0.0-pre.39","tslint":"^5.16.0","tslint-config-prettier":"^1.18.0","typescript":"^3.4.5","typescript-tslint-plugin":"^0.3.1"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@1.2.0","dist":{"shasum":"443462e9948b58837c02642d6d51ab2632e09d84","integrity":"sha512-c82Pjb011lNUv0ATy45H9ICfciyeEhPPkHhHrlJWiITSiakN9FzaPIODgZD8RYvdXi6TZS9LPDxcyHxsYbJPCA==","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-1.2.0.tgz","fileCount":20,"unpackedSize":30769,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc1xEmCRA9TVsSAnZWagAABw0P/3OWDktoIc418zLMAxup\nBHx3HRymi5y9HS4CC7nzcbewztWhms8/ekwV+cyXVAsO2n2PzI/sgLLXozwK\nYhF8GOCt+T6IUpCUaMshUmwhnXP2nS8xmzarjuNt2eyJFmet4za0pqcXpZW2\nOgicVgdSuNvi5lK65saBWEufXPGtEi9gElz5OZW3mFk8P2NSkvBw17rqG0Ou\njs8Qr/0TOeZ73fNbYug5YYi3tllRq5lJDRPjC7vV2hJ6WteikANbAHC4ppcL\nEwT59PqfvD4a9u3yjUTZ2dPM9WEDg09zY8AT1SA2AlrlTOtHeJSGGy8xsPMH\n0gJrtgc0QkQkvYTSYVK/Tav+y0G0mxWN1o4fvFLtyvNEyD3ekBK/PerIx8xf\nLQeDGAf2fDT7+gEmOcDi6/HazlGPqTrsqzWGwMreo8f06Pbog9Zm7UkLrGFz\nLLRWS+fXz/KwjSr/2XUO459FtNjwQjfaZyM/LVbyXFIBZkJON7WmUdEHpSGe\nORpGD/omd7XOuN443cWnkWIOwhzvrJqoCHlig24GJBcEHjOTXV7f1zPBaZd1\nj7vQPMRsoM5avqvmH2cPlBmoWdDd8EB/o3Mp+q1K+HjXsl5jmXH1djWmHSOG\nyJB2FXTSi8qsUvLjpROK2QIftfEBJRJirHWY2VfLLdFZz1HQNdTTgBJgXrkb\nvt9Q\r\n=ABcZ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIC8fXbUJmK32QmJJqyiEqCPhh8LqYPl5zQ5zXxac1w8vAiEArrr7DRYEqAo1AM1fz3/bz64Wpw1fhQeAo4vEEE2yWug="}]},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_1.2.0_1557598502091_0.970865884190325"},"_hasShrinkwrap":false},"1.2.1":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"1.2.1","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist/bin.js"},"engines":{"node":">=8.10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest","test:watch":"jest --watch --verbose false"},"dependencies":{"bcryptjs":"^2.4.3","body-parser":"^1.19.0","express":"^4.17.1","json-server":"^0.15.0","jsonwebtoken":"^8.5.1","yargs":"^13.2.4"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/express":"^4.17.0","@types/jest":"^24.0.14","@types/json-server":"^0.14.0","@types/jsonwebtoken":"^8.3.2","@types/supertest":"^2.0.7","@types/yargs":"^13.0.0","jest":"^24.8.0","rimraf":"^2.6.3","supertest":"^4.0.2","tree-kill":"^1.2.1","ts-jest":"^24.0.2","ts-node-dev":"^1.0.0-pre.40","tslint":"^5.17.0","tslint-config-prettier":"^1.18.0","typescript":"^3.5.2","typescript-tslint-plugin":"^0.5.0"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@1.2.1","dist":{"shasum":"00c2e6e4930eeb2b16d01ac3f297a8270b672643","integrity":"sha512-NDYkQW7SYFr7dm/r9QW6iKPDvpa0KMeINrHFqklmO1kdfJSjpMr/wtbyZrd9kMspjyETNmOGYyg0HpbviONesA==","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-1.2.1.tgz","fileCount":20,"unpackedSize":31558,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdBTyuCRA9TVsSAnZWagAAFhQP/RS7nsOAhCTLFvEV7Wm6\npmzyrY1PbaT+NYs5wxXsl1n9jdtSkmRXL+vB8vXF7sETa8Ku5PlyoA5glwfz\ncLlkV/YBNauqoKMPIAGdt7pIaWDbBEalbprGP3jUt1907vxDPJQMzgmrmwBM\n0zDy2ecww9kOfTn3sVDjsGoMiTSYOHC+hoxiEAqyTX1f81VyDbhlno39Z1pK\n14TGszh/PhDG/pjAMh24Gk5Ni1WlOh+NOJzpodYjDnJ/csyW1ov6+QMW5wX4\nvqasbxnFZbs9y5DxSMiMmIcB4zN3+/DQC+8QbwOc49hCS8wn/jKlp46f+dAd\n5QQomQENhB3dpbMNsZdVmTB6Coa+sJgq15synnr76ukizUIyLQFceBZLdcaT\nhBp+curDFqtgn299d2HPsqmHALXa+4s/JsBwtp2vBxlcklhz5F6X9lJrPRX1\npNPqA30oUQ6toB8oxTwoDHP82/PbRGfWNvjAnCBwMGELpNA7jz5UQ4wEsoxY\nBMzdb4jv3HBgRlX1SYUb4DGPrn84yb8OukOS28InDH94OBvksO91c8HpeZkL\nFaeCbu6G0kDE9HLxVKNTgzUen+xfkL8PqiewSK0wmIxP/Rylj+PWfCFJl4gn\njnSD80pUjOOS5oAeXCJHqxdAyPSVzE8wIQbGAEeT/A9xgL1iKmCQKkyw4iMr\nair+\r\n=Hpw5\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDbd4NZsNB28gB8ImdaF5+IZ2vZA3OV57YtlIgUsdM8wAiBXbDc/M9pktFMjuCMnk4nwNd2LfrbQYhtgDvmaQgNSbA=="}]},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_1.2.1_1560624301517_0.5965624725399397"},"_hasShrinkwrap":false},"2.0.0":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"2.0.0","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist\\bin.js"},"engines":{"node":">=10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest","test:file":"jest --testPathPattern","test:watch":"jest --watch --verbose false","release":"standard-version"},"peerDependencies":{"json-server":"^0.15"},"dependencies":{"bcryptjs":"^2.4.3","jsonwebtoken":"^8.5.1","yargs":"^15.3.1"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/express":"^4.17.6","@types/jest":"^25.2.3","@types/json-server":"^0.14.2","@types/jsonwebtoken":"^8.5.0","@types/supertest":"^2.0.9","@types/yargs":"^15.0.5","express":"^4.17.1","jest":"^26.0.1","json-server":"^0.16.1","rimraf":"^3.0.2","standard-version":"^8.0.0","supertest":"^4.0.2","tree-kill":"^1.2.2","ts-jest":"^26.1.0","ts-node-dev":"^1.0.0-pre.44","tslint":"^6.1.2","tslint-config-prettier":"^1.18.0","typescript":"^3.9.3","typescript-tslint-plugin":"^0.5.5"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@2.0.0","dist":{"shasum":"d93c562ad72224246a9d2596925972324ba11208","integrity":"sha512-v9hvnpxDz37M9Xhv5IGHE5jwAOhiCFvsTVWVvbSihyaZfWIHVVQ31RBd/PHKigRmZtdoM1QQ22kIHzu6N5Jshg==","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-2.0.0.tgz","fileCount":21,"unpackedSize":32320,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe1D4uCRA9TVsSAnZWagAAPH8P/1hMrU9cklJNBsitq2tR\nWYZxX0snK1F/4rBKHAfMW/eF2HA5xsctx5EyfvYho7zqJY3LaKHiU+paG69A\ncf6mfAMfW1+VDp+apRKsyGL1OPymgH8McGqX5rGZYrVz/AX3xH5ziclYFew8\npeCAxQqhg2yy9SSqRm8yAKKCV6Z5b+cT94GG8mHCxA2Zcl4Q0HBn3k/skEem\neKCUu+RLIWwrmhmP5FsGW+JlQ779RmiYz2NMOrDvZsm9SAjLetCfIA5hXmXw\nkBO5pSiDS6XqeUdR+z7YyGa++B92J9kcnvQjV2LaWsk6tiZYX54nwBvrrkpz\ntmnFlVXohvG2qMymFxy/uku0wQOqTkT0aYAxS2YV2n2NGRbohjkm8a/csu1U\nAEV7J1tY1E/K05lVlMFXqVGz0udiZuR3lKEebbjypYNSRu5JVRmgbYyT3f+f\nshStrFRHaemBmHInWHNchPIc2gZ/BOcOnmwEukq+wh2nzAAmv6naDCuRvUOF\nwte7DBb0hlI+KLljlRxRXo9X372XbcnLPzpyfdoAphAgQSSIWOxLiTHgGby2\nX0n8rkHu3+PWjm7UuvNKsXLlG7qb8bb+YxoLhuet/h0MwoPeVvv1c7H6Fsq3\nEYlVI1mQk+xmpE/1clIzg8mFu9BJRaX7Zqd/AK2lztGrgiCpQvDhzpw6xvCd\ngvzT\r\n=Sv4G\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIE9AptvVc1iSfYtTdwnBAoJL2vcSPnRF8WaXnCe6Z7JOAiEApAJEWXConyGkk9CMj72XZS3/QG/A8IwcNyXIficeIZw="}]},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_2.0.0_1590967853577_0.5030743664409303"},"_hasShrinkwrap":false},"2.0.1":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"2.0.1","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist\\bin.js"},"engines":{"node":">=10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest","test:file":"jest --testPathPattern","test:watch":"jest --watch --verbose false","release":"standard-version"},"peerDependencies":{"json-server":"^0.15"},"dependencies":{"bcryptjs":"^2.4.3","jsonwebtoken":"^8.5.1","yargs":"^15.3.1"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/express":"^4.17.6","@types/jest":"^25.2.3","@types/json-server":"^0.14.2","@types/jsonwebtoken":"^8.5.0","@types/supertest":"^2.0.9","@types/yargs":"^15.0.5","express":"^4.17.1","jest":"^26.0.1","json-server":"^0.16.1","rimraf":"^3.0.2","standard-version":"^8.0.0","supertest":"^4.0.2","tree-kill":"^1.2.2","ts-jest":"^26.1.0","ts-node-dev":"^1.0.0-pre.44","tslint":"^6.1.2","tslint-config-prettier":"^1.18.0","typescript":"^3.9.3","typescript-tslint-plugin":"^0.5.5"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@2.0.1","dist":{"shasum":"e22a413b16e5a9152f05bb26ec088782d0cc5e3d","integrity":"sha512-VMovr2hOkuPoF0fBGpESZrfk9nhnrI1Pf22KUAm/3T6phuFIFkccX2JrYLKqDmN0krQaJfmQHiTjJbBZc99now==","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-2.0.1.tgz","fileCount":21,"unpackedSize":32601,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe1QrGCRA9TVsSAnZWagAAF8gP/iy55EMkQq2rZlkNo92N\nJgW9c90mO2ZF4frMiIGiIF/GNK5SpLHLjduJu5Gs53DS4A13gERVSZ7NNn0V\nSRQIg8KjM+tkSu6Pgi04SU7nl4kvyKRamMsYx90V5o8oe3S0V9NnLyP4gZpu\nuVdkZ7hudR0ke+/7jdOTcqoSkgdHD/u7gQeSsMmw83VEeGx8pHHm5QkCqbFr\nUw/Up7BKUK7IDUnaQuKAFfKU1Ar0MjXVm6SIZP1eLjo8uZFT0EjGi7bH7c1N\nLl1EE/yVsHKEso2Uib3TImmblyW1j9ERe7mYU4vlPSxiz3lS9L1bi1KNEWxl\npTM6hCxj0oKZdaYzZdGrpE8Hh0p6T3vVvwyN2eYL3LMlqCl9gxTUPhu8Y+fJ\njiuNBo9vJfSsSI1eb1xl8j28ZAn+Y0mI+btBocqNp83w9VtsSDbAvheAg9eO\n6d84yeV65D5ySZql6aHM7/pnKy2bofOU+d2UIp0iQ8e4gxHdmLTuF9JNcylc\nAT7t9Adz9wV3QfgIp+cMSVPxgubNkR+MtT1BxliVroVDOLT1KZInj1tzRrOJ\noc1D91Qe57uStNtC+Qck+8k87hO6i2AquE5b59JtVY0CFrZcL+AhaaXJwjYF\ngcWRV30dmvTBcBupSosXf8c7fkxdEXJcbCPof+IedOGh1u0EewZ26TVD3Pue\nL4Jz\r\n=X8ML\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDg/tdqsNGec4MpxThBlKEVUSO9NDtUQt6lzcAXa2luKQIhAPoMGCXmN3HoOBtAJMEwXE8O6TgUGjXU/TzSWWZvBdWh"}]},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_2.0.1_1591020230258_0.43799926247723087"},"_hasShrinkwrap":false},"2.0.2":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"2.0.2","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist\\bin.js"},"engines":{"node":">=10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest","test:file":"jest --testPathPattern","test:watch":"jest --watch --verbose false","release":"standard-version"},"peerDependencies":{"json-server":"^0.15"},"dependencies":{"bcryptjs":"^2.4.3","jsonwebtoken":"^8.5.1","yargs":"^15.3.1"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/express":"^4.17.6","@types/jest":"^25.2.3","@types/json-server":"^0.14.2","@types/jsonwebtoken":"^8.5.0","@types/supertest":"^2.0.9","@types/yargs":"^15.0.5","express":"^4.17.1","jest":"^26.0.1","json-server":"^0.16.1","rimraf":"^3.0.2","standard-version":"^8.0.0","supertest":"^4.0.2","tree-kill":"^1.2.2","ts-jest":"^26.1.0","ts-node-dev":"^1.0.0-pre.44","tslint":"^6.1.2","tslint-config-prettier":"^1.18.0","typescript":"^3.9.3","typescript-tslint-plugin":"^0.5.5"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@2.0.2","dist":{"shasum":"5a19cf45924030317a64998d9d437278577f4d55","integrity":"sha512-O1b2CFtrUGKMwR02AglZb2A5FSpnAgrE6f6bYXnWwwr+wBH/dfB8tJx/PffOhUB2fez9d0URqvCeVOJ7PyIPug==","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-2.0.2.tgz","fileCount":21,"unpackedSize":33260,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe1V5ZCRA9TVsSAnZWagAAAvEP/0Y9/wHSz4qwN9e4j4tJ\nuHJBNBhFE+sWWdy4JMKTY0aZA3p6q3DnwddFODuB4TONwlMTESQIXlg6fZ8x\n8j2OtJ7beVgdvqPEJ5qmWasf+s6PoWOjdrDBrcqcjXD5OIh5gJ7ATBiE2/P4\nEAQyXZikaA/CeT7Gh6EYWuu6ArrUAKczexPypgumNt/Q3XaMAzosMf0VqCvb\n/yuT7SK0cvgNkyALDZY4bQOJiWbJDU7zlsdnXpBt9rWdSEf9WRIituzQIAv0\n4y/fIq7BUCcnzpZDcGndW90FSEBoxz2iLm12S1628WyDDwZpoQkwHQ0PvQ4w\na35gC0ANEwk0GkK7765rQ516p2l93Z3uKshMyF0B2OccDRNniyE0Yg1fGwjm\nlAugFjgm2wA12GRLz1Cg5ZRCd07+/M5GOfwhEI25G9gFTaSVzE74QKHeFf62\nOCm2nS9Kq470YM6pG96dDRHgEdBXIhRdmjdVNGJGUPKOAs8PsdtU2+UHmZy5\nj+GqPseoDKWAVrFLSYETVh7IUh8P7Qj+D6fpvy5ovHDqf7TAEqOS8PgXgVbW\n49WO0gxLj9wju+CYXuM1qIyKWWLpQyQ91DetZyjjfW+mDrBDazN1P0gbaDy2\nLSFSjxBHwhzUohAlyTdGk4OTa6SmMxeYjVYOa/kBmQHaNdsChYDXJCx+X2kB\nblHS\r\n=G2JZ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC+GT+ef1OEJ9gqu3eqHB6QyHZxTqV+txKyt2FSfO5dAQIgCeDnM0XnWLIUee8fKzdpgsD+jwBdiu/qxVk+1HG7pto="}]},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_2.0.2_1591041624344_0.405777259933247"},"_hasShrinkwrap":false},"2.0.3":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"2.0.3","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist\\bin.js"},"engines":{"node":">=10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest","test:file":"jest --testPathPattern","test:watch":"jest --watch --verbose false","release":"standard-version"},"peerDependencies":{"json-server":"^0.15"},"dependencies":{"bcryptjs":"^2.4.3","jsonwebtoken":"^8.5.1","yargs":"^16.2.0"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/jest":"^26.0.24","@types/json-server":"^0.14.4","@types/jsonwebtoken":"^8.5.4","@types/supertest":"^2.0.11","@types/yargs":"^16.0.0","jest":"^27.0.6","json-server":"^0.16.3","rimraf":"^3.0.2","standard-version":"^9.3.1","supertest":"^6.1.4","tree-kill":"^1.2.2","ts-jest":"^27.0.4","ts-node-dev":"^1.1.8","tslint":"^6.1.3","tslint-config-prettier":"^1.18.0","typescript":"^4.3.5","typescript-tslint-plugin":"^1.0.1"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"readmeFilename":"README.MD","readme":"# 🔐 JSON Server Auth\n\nJWT authentication middleware for **[JSON Server](https://github.com/typicode/json-server)**\n\nBecause you also need a fake **authentication & authorization flow** for your prototyping.\n\n## Getting started\n\nInstall **both** JSON Server and JSON Server Auth :\n\n```bash\n# NPM\nnpm install -D json-server json-server-auth\n\n# Yarn\nyarn add -D json-server json-server-auth\n```\n\nCreate a `db.json` file with a `users` collection :\n\n```json\n{\n  \"users\": []\n}\n```\n\nStart JSON server (with _JSON server Auth_ as middleware) :\n\n```bash\njson-server db.json -m ./node_modules/json-server-auth\n# with json-server installed globally and json-server-auth installed locally\n```\n\n##### 📢 but wait !\n\nAs a convenience, **`json-server-auth`** CLI exposes `json-server` bundled with its middlewares :\n\n```bash\njson-server-auth db.json\n# with json-server-auth installed globally\n```\n\n_It exposes and works the same for all [JSON Server flags](https://github.com/typicode/json-server#cli-usage)._\n\n## Authentication flow 🔑\n\nJSON Server Auth adds a simple [JWT based](https://jwt.io/) authentication flow.\n\n### Register 👥\n\nAny of the following routes registers a new user :\n\n- **`POST /register`**\n- **`POST /signup`**\n- **`POST /users`**\n\n**`email`** and **`password`** are required in the request body :\n\n```http\nPOST /register\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\"\n}\n```\n\nThe password is encrypted by [bcryptjs](https://github.com/dcodeIO/bcrypt.js).\nThe response contains the JWT access token (expiration time of 1 hour) :\n\n```http\n201 Created\n{\n  \"accessToken\": \"xxx.xxx.xxx\"\n}\n```\n\n###### Other properties\n\nAny other property can be added to the request body without being validated :\n\n```http\nPOST /register\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\",\n  \"firstname\": \"Olivier\",\n  \"lastname\": \"Monge\",\n  \"age\": 32\n}\n```\n\n###### Update\n\nAny update to an existing user (via `PATCH` or `PUT` methods) will go through the same process for `email` and `password`.\n\n### Login 🛂\n\nAny of the following routes logs an existing user in :\n\n- **`POST /login`**\n- **`POST /signin`**\n\n**`email`** and **`password`** are required, of course :\n\n```http\nPOST /login\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\"\n}\n```\n\nThe response contains the JWT access token (expiration time of 1 hour) :\n\n```http\n200 OK\n{\n  \"accessToken\": \"xxx.xxx.xxx\"\n}\n```\n\n#### JWT payload 📇\n\nThe access token has the following claims :\n\n- **`sub` :** the user `id` (as per the [JWT specs](https://tools.ietf.org/html/rfc7519#section-4.1.2)).\n- **`email` :** the user `email`.\n\n## Authorization flow 🛡️\n\nJSON Server Auth provides generic guards as **route middlewares**.\n\nTo handle common use cases, JSON Server Auth draws inspiration from **Unix filesystem permissions**, especialy the [numeric notation](https://en.wikipedia.org/wiki/File_system_permissions#Numeric_notation).\n\n- We add **`4`** for **read** permission.\n- We add **`2`** for **write** permission.\n\n_Of course CRUD is not a filesystem, so we don't add 1 for execute permission._\n\nSimilarly to Unix, we then have three digits to match each user type :\n\n- First digit are the permissions for the **resource owner**.\n- Second digit are the permissions for the **logged-in users**.\n- Third digit are the permissions for the **public users**.\n\nFor example, **`640`** means that only the owner can write the resource, logged-in users can read the resource, and public users cannot access the resource at all.\n\n#### The resource owner 🛀\n\nA user is the owner of a resource if that resource has a **`userId`** property that matches his `id` property. Example:\n\n```js\n// The owner of\n{ id: 8, text: 'blabla', userId: 1 }\n// is\n{ id: 1, email: 'olivier@mail.com' }\n```\n\nPrivate guarded routes will use the JWT `sub` claim (which equals the user `id`) to check if the user actually owns the requested resource, by comparing `sub` with the `userId` property.\n\n_Except for the actual `users` collection, where the JWT `sub` claim must match the `id` property._\n\n### Guarded routes 🚥\n\nGuarded routes exist at the root and can restrict access to any resource you put after them :\n\n|    Route     | Resource permissions                                                                                 |\n| :----------: | :--------------------------------------------------------------------------------------------------- |\n| **`/664/*`** | User must be logged to _write_ the resource. <br> Everyone can _read_ the resource.                  |\n| **`/660/*`** | User must be logged to _write_ or _read_ the resource.                                               |\n| **`/644/*`** | User must own the resource to _write_ the resource. <br> Everyone can _read_ the resource.           |\n| **`/640/*`** | User must own the resource to _write_ the resource. <br> User must be logged to _read_ the resource. |\n| **`/600/*`** | User must own the resource to _write_ or _read_ the resource.                                        |\n| **`/444/*`** | No one can _write_ the resource. <br> Everyone can _read_ the resource.                              |\n| **`/440/*`** | No one can _write_ the resource. <br> User must be logged to _read_ the resource.                    |\n| **`/400/*`** | No one can _write_ the resource. <br> User must own the resource to _read_ the resource.             |\n\n#### Examples\n\n- Public user (not logged-in) does the following requests : \n\n| _Request_                               | _Response_         |\n| :-------------------------------------- | :----------------- |\n| `GET /664/posts`                        | `200 OK`           |\n| `POST /664/posts`<br>`{text: 'blabla'}` | `401 UNAUTHORIZED` |\n\n- Logged-in user with `id: 1` does the following requests :\n\n| _Request_                                                  | _Response_      |\n| :--------------------------------------------------------- | :-------------- |\n| `GET /600/users/1`<br>`Authorization: Bearer xxx.xxx.xxx`  | `200 OK`        |\n| `GET /600/users/23`<br>`Authorization: Bearer xxx.xxx.xxx` | `403 FORBIDDEN` |\n\n### Setup permissions 💡\n\nOf course, you don't want to directly use guarded routes in your requests.\nWe can take advantage of [JSON Server custom routes feature](https://github.com/typicode/json-server#add-custom-routes) to setup resource permissions ahead.\n\nCreate a `routes.json` file :\n\n```json\n{\n  \"/users*\": \"/600/users$1\",\n  \"/messages*\": \"/640/messages$1\"\n}\n```\n\nThen :\n\n```bash\njson-server db.json -m ./node_modules/json-server-auth -r routes.json\n# with json-server installed globally and json-server-auth installed locally\n```\n\n##### 📢 but wait !\n\nAs a convenience, **`json-server-auth`** CLI allows you to define permissions in a more succinct way :\n\n```json\n{\n  \"users\": 600,\n  \"messages\": 640\n}\n```\n\nThen :\n\n```bash\njson-server-auth db.json -r routes.json\n# with json-server-auth installed globally\n```\n\nYou can still add any other _normal_ custom routes :\n\n```json\n{\n  \"users\": 600,\n  \"messages\": 640,\n  \"/posts/:category\": \"/posts?category=:category\"\n}\n```\n\n## Module usage 🔩\n\nIf you go the programmatic way and [use JSON Server as a module](https://github.com/typicode/json-server#module), there is an extra step to properly integrate JSON Server Auth :\n\n⚠️ You must bind the router property `db` to the created app, like the [JSON Server CLI does](https://github.com/typicode/json-server/blob/master/src/cli/run.js#L74), and you must apply the middlewares in a specific order.\n\n```js\nconst jsonServer = require('json-server')\nconst auth = require('json-server-auth')\n\nconst app = jsonServer.create()\nconst router = jsonServer.router('db.json')\n\n// /!\\ Bind the router db to the app\napp.db = router.db\n\n// You must apply the auth middleware before the router\napp.use(auth)\napp.use(router)\napp.listen(3000)\n```\n\n#### Permisssions Rewriter\n\nThe custom rewriter is accessible via a subproperty :\n\n```js\nconst auth = require('json-server-auth')\n\nconst rules = auth.rewriter({\n  // Permission rules\n  users: 600,\n  messages: 640,\n  // Other rules\n  '/posts/:category': '/posts?category=:category',\n})\n\n// You must apply the middlewares in the following order\napp.use(rules)\napp.use(auth)\napp.use(router)\n```\n\n## TODO 📜\n\n- [ ] Use JSON Server `id` and `foreignKeySuffix` parameters\n- [ ] Handle query params in list requests to secure guarded routes more precisely\n- [ ] Allow configuration of :\n  - [ ] Users collection name\n  - [ ] Minimum password length\n  - [ ] JWT expiry time\n  - [ ] JWT property name in response\n- [ ] Implement JWT Refresh Token\n- [ ] Possibility to disable password encryption ?\n","licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@2.0.3","dist":{"shasum":"5cf470a42550068d82e833470d1d80ec1ddeb8c8","integrity":"sha512-8dLxIL9UqdsWMP07p9YXrW3wt42tXSesXKqzjovQZBac89J0EiVIdAg3Bt5UhR7xpfVXl1rsWjaQx74mQA7bOA==","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-2.0.3.tgz","fileCount":21,"unpackedSize":35097,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJg+HqqCRA9TVsSAnZWagAAFggP/1reF1K9W3N8N3RShJKd\ngsY2crszV9u33kf2O4A0w/Q8iwc7H86Ng2UsYkZ5twrWK18YN2d4RCoWYpC9\nkhOVylYqxUGk7rPeWcsjxQRSu5rPpBfjZW5q2jJN/4VrxK3rjWVCDlkqgB0D\ncl+K6QmhZnOotAWfni8pXjd3xIshlbcHB39u95YgrS5gWVN+k0JaAtEhl/e3\nxrQ2pqxIzwCtYAH9pQzRw03yBe1PAubA3yxNXzbgtDt1752y1dlQFu0OY95h\n/PEO+MsfOMbJWJNpG3q6Yfi3Zqqh63N1QtSU2zzszjjCXO3R0MQf+rRUeN5/\nDYIcpqca3S22MXr4dRS+7Tvf+V446qOrBzXEQR1WoIrgE0Uhk7hLFT+Cwh3S\nRDEKqWjLH6vgr48Mr6Blgq5wQehebuo29WahfSAJl+Ukxze1dk1YpYpHXXxi\n3AHGpmhIdszB30FDGayKBxohRSA98znyz2AEKGN51JpYH+e+hcSawgDHouSW\nMKuSF2l4BajEgkyv4Je6JKyv8yummWUuv83dZDhk/lffIMQwts1ObKep4Zrj\nGIAI1uBbhANlvPfjk6Ce0nVphq+HT33jTarWtmn+HAV8Nm3tMiL+et3MnAZP\nONxRNG0DUjVVVSAQ47G1BwLBkYioiMwYnDf/qGi3DOFRFmVOSGLb6ytjq0lX\n69Tv\r\n=U7G3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDeRi00urwCc1//MJGToas8AoQfAJmWbfBNGveiDw6PHgIgdWq2dwP8oggFdEqBxg3+EwqzQdohqMctKj7EQXHqUY8="}]},"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_2.0.3_1626897066676_0.7833382654682073"},"_hasShrinkwrap":false},"2.0.3-b":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"2.0.3-b","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist\\bin.js"},"engines":{"node":">=10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest","test:file":"jest --testPathPattern","test:watch":"jest --watch --verbose false","release":"standard-version"},"peerDependencies":{"json-server":"*"},"dependencies":{"bcryptjs":"^2.4.3","jsonwebtoken":"^8.5.1","yargs":"^16.2.0"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/jest":"^26.0.24","@types/json-server":"^0.14.4","@types/jsonwebtoken":"^8.5.4","@types/supertest":"^2.0.11","@types/yargs":"^16.0.0","jest":"^27.0.6","json-server":"^0.16.3","rimraf":"^3.0.2","standard-version":"^9.3.1","supertest":"^6.1.4","tree-kill":"^1.2.2","ts-jest":"^27.0.4","ts-node-dev":"^1.1.8","tslint":"^6.1.3","tslint-config-prettier":"^1.18.0","typescript":"^4.3.5","typescript-tslint-plugin":"^1.0.1"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"readmeFilename":"README.MD","readme":"# 🔐 JSON Server Auth\n\nJWT authentication middleware for **[JSON Server](https://github.com/typicode/json-server)**\n\nBecause you also need a fake **authentication & authorization flow** for your prototyping.\n\n## Getting started\n\nInstall **both** JSON Server and JSON Server Auth :\n\n```bash\n# NPM\nnpm install -D json-server json-server-auth\n\n# Yarn\nyarn add -D json-server json-server-auth\n```\n\nCreate a `db.json` file with a `users` collection :\n\n```json\n{\n  \"users\": []\n}\n```\n\nStart JSON server (with _JSON server Auth_ as middleware) :\n\n```bash\njson-server db.json -m ./node_modules/json-server-auth\n# with json-server installed globally and json-server-auth installed locally\n```\n\n##### 📢 but wait !\n\nAs a convenience, **`json-server-auth`** CLI exposes `json-server` bundled with its middlewares :\n\n```bash\njson-server-auth db.json\n# with json-server-auth installed globally\n```\n\n_It exposes and works the same for all [JSON Server flags](https://github.com/typicode/json-server#cli-usage)._\n\n## Authentication flow 🔑\n\nJSON Server Auth adds a simple [JWT based](https://jwt.io/) authentication flow.\n\n### Register 👥\n\nAny of the following routes registers a new user :\n\n- **`POST /register`**\n- **`POST /signup`**\n- **`POST /users`**\n\n**`email`** and **`password`** are required in the request body :\n\n```http\nPOST /register\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\"\n}\n```\n\nThe password is encrypted by [bcryptjs](https://github.com/dcodeIO/bcrypt.js).\nThe response contains the JWT access token (expiration time of 1 hour) :\n\n```http\n201 Created\n{\n  \"accessToken\": \"xxx.xxx.xxx\"\n}\n```\n\n###### Other properties\n\nAny other property can be added to the request body without being validated :\n\n```http\nPOST /register\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\",\n  \"firstname\": \"Olivier\",\n  \"lastname\": \"Monge\",\n  \"age\": 32\n}\n```\n\n###### Update\n\nAny update to an existing user (via `PATCH` or `PUT` methods) will go through the same process for `email` and `password`.\n\n### Login 🛂\n\nAny of the following routes logs an existing user in :\n\n- **`POST /login`**\n- **`POST /signin`**\n\n**`email`** and **`password`** are required, of course :\n\n```http\nPOST /login\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\"\n}\n```\n\nThe response contains the JWT access token (expiration time of 1 hour) :\n\n```http\n200 OK\n{\n  \"accessToken\": \"xxx.xxx.xxx\"\n}\n```\n\n#### JWT payload 📇\n\nThe access token has the following claims :\n\n- **`sub` :** the user `id` (as per the [JWT specs](https://tools.ietf.org/html/rfc7519#section-4.1.2)).\n- **`email` :** the user `email`.\n\n## Authorization flow 🛡️\n\nJSON Server Auth provides generic guards as **route middlewares**.\n\nTo handle common use cases, JSON Server Auth draws inspiration from **Unix filesystem permissions**, especialy the [numeric notation](https://en.wikipedia.org/wiki/File_system_permissions#Numeric_notation).\n\n- We add **`4`** for **read** permission.\n- We add **`2`** for **write** permission.\n\n_Of course CRUD is not a filesystem, so we don't add 1 for execute permission._\n\nSimilarly to Unix, we then have three digits to match each user type :\n\n- First digit are the permissions for the **resource owner**.\n- Second digit are the permissions for the **logged-in users**.\n- Third digit are the permissions for the **public users**.\n\nFor example, **`640`** means that only the owner can write the resource, logged-in users can read the resource, and public users cannot access the resource at all.\n\n#### The resource owner 🛀\n\nA user is the owner of a resource if that resource has a **`userId`** property that matches his `id` property. Example:\n\n```js\n// The owner of\n{ id: 8, text: 'blabla', userId: 1 }\n// is\n{ id: 1, email: 'olivier@mail.com' }\n```\n\nPrivate guarded routes will use the JWT `sub` claim (which equals the user `id`) to check if the user actually owns the requested resource, by comparing `sub` with the `userId` property.\n\n_Except for the actual `users` collection, where the JWT `sub` claim must match the `id` property._\n\n### Guarded routes 🚥\n\nGuarded routes exist at the root and can restrict access to any resource you put after them :\n\n|    Route     | Resource permissions                                                                                 |\n| :----------: | :--------------------------------------------------------------------------------------------------- |\n| **`/664/*`** | User must be logged to _write_ the resource. <br> Everyone can _read_ the resource.                  |\n| **`/660/*`** | User must be logged to _write_ or _read_ the resource.                                               |\n| **`/644/*`** | User must own the resource to _write_ the resource. <br> Everyone can _read_ the resource.           |\n| **`/640/*`** | User must own the resource to _write_ the resource. <br> User must be logged to _read_ the resource. |\n| **`/600/*`** | User must own the resource to _write_ or _read_ the resource.                                        |\n| **`/444/*`** | No one can _write_ the resource. <br> Everyone can _read_ the resource.                              |\n| **`/440/*`** | No one can _write_ the resource. <br> User must be logged to _read_ the resource.                    |\n| **`/400/*`** | No one can _write_ the resource. <br> User must own the resource to _read_ the resource.             |\n\n#### Examples\n\n- Public user (not logged-in) does the following requests : \n\n| _Request_                               | _Response_         |\n| :-------------------------------------- | :----------------- |\n| `GET /664/posts`                        | `200 OK`           |\n| `POST /664/posts`<br>`{text: 'blabla'}` | `401 UNAUTHORIZED` |\n\n- Logged-in user with `id: 1` does the following requests :\n\n| _Request_                                                  | _Response_      |\n| :--------------------------------------------------------- | :-------------- |\n| `GET /600/users/1`<br>`Authorization: Bearer xxx.xxx.xxx`  | `200 OK`        |\n| `GET /600/users/23`<br>`Authorization: Bearer xxx.xxx.xxx` | `403 FORBIDDEN` |\n\n### Setup permissions 💡\n\nOf course, you don't want to directly use guarded routes in your requests.\nWe can take advantage of [JSON Server custom routes feature](https://github.com/typicode/json-server#add-custom-routes) to setup resource permissions ahead.\n\nCreate a `routes.json` file :\n\n```json\n{\n  \"/users*\": \"/600/users$1\",\n  \"/messages*\": \"/640/messages$1\"\n}\n```\n\nThen :\n\n```bash\njson-server db.json -m ./node_modules/json-server-auth -r routes.json\n# with json-server installed globally and json-server-auth installed locally\n```\n\n##### 📢 but wait !\n\nAs a convenience, **`json-server-auth`** CLI allows you to define permissions in a more succinct way :\n\n```json\n{\n  \"users\": 600,\n  \"messages\": 640\n}\n```\n\nThen :\n\n```bash\njson-server-auth db.json -r routes.json\n# with json-server-auth installed globally\n```\n\nYou can still add any other _normal_ custom routes :\n\n```json\n{\n  \"users\": 600,\n  \"messages\": 640,\n  \"/posts/:category\": \"/posts?category=:category\"\n}\n```\n\n## Module usage 🔩\n\nIf you go the programmatic way and [use JSON Server as a module](https://github.com/typicode/json-server#module), there is an extra step to properly integrate JSON Server Auth :\n\n⚠️ You must bind the router property `db` to the created app, like the [JSON Server CLI does](https://github.com/typicode/json-server/blob/master/src/cli/run.js#L74), and you must apply the middlewares in a specific order.\n\n```js\nconst jsonServer = require('json-server')\nconst auth = require('json-server-auth')\n\nconst app = jsonServer.create()\nconst router = jsonServer.router('db.json')\n\n// /!\\ Bind the router db to the app\napp.db = router.db\n\n// You must apply the auth middleware before the router\napp.use(auth)\napp.use(router)\napp.listen(3000)\n```\n\n#### Permisssions Rewriter\n\nThe custom rewriter is accessible via a subproperty :\n\n```js\nconst auth = require('json-server-auth')\n\nconst rules = auth.rewriter({\n  // Permission rules\n  users: 600,\n  messages: 640,\n  // Other rules\n  '/posts/:category': '/posts?category=:category',\n})\n\n// You must apply the middlewares in the following order\napp.use(rules)\napp.use(auth)\napp.use(router)\n```\n\n## TODO 📜\n\n- [ ] Use JSON Server `id` and `foreignKeySuffix` parameters\n- [ ] Handle query params in list requests to secure guarded routes more precisely\n- [ ] Allow configuration of :\n  - [ ] Users collection name\n  - [ ] Minimum password length\n  - [ ] JWT expiry time\n  - [ ] JWT property name in response\n- [ ] Implement JWT Refresh Token\n- [ ] Possibility to disable password encryption ?\n","licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@2.0.3-b","dist":{"shasum":"9ebb2284495aea39c7c72d9adaf19c40d45cbe64","integrity":"sha512-8mdE/pmxWTVNn2WqCmE3mvT//KOwah65XqPWjSDzWkSfPpL4AmhlOTAEqPSPjXwnyjQK0XZV8QMjZuwPv6qeiA==","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-2.0.3-b.tgz","fileCount":21,"unpackedSize":35095,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJg+Hx7CRA9TVsSAnZWagAAiLAP/2ohHNgK4kYogKdYls7X\n/K54E2IZ0JfADjP+gOpPUFcAn5ncRTs9EW4/48RfSQdvxBZNHM0GZKDtXCy3\nsdM0eK1kO8GBwNLsaeaPfMXDYmIE5pupLX6uYkXhNaaiVfia5F7YMzW71YUW\n0ns/4Y3KyA+RHeQHmx1/dG2E3w0KdSimJ6THuAAHU/41nJCdtx9pCzvB7csv\nMnmi1YzKT9T45uqIN1l7r6l9aDIF71vHTzMRjNdwmzPtnU94ZtKtZkMTZ4Cs\nc/AswfLgNvZ9VGFdBBjUZlawn+v0eXAjSXPaKboyWjgxfTmpOn8uagTu6A6k\nB45EKYN/Iw/Lp8NWGnowdSnom5k1Xocbf0zJ0qh7pb4R6E79LJyVrxt2rAKK\n2VSNvc5zuhpyq0SGnxvV10b4AjzsUYvlODFBvLRkxaZLynH4azbSKti+AQsM\naH5p7SBYlQ0xcRB7MxpB37FCJK5s682tIUCMrv6xVzLt0CnCEccf43A/mZ1x\n4DKjSe12Da5XKnktwFHSRESAFQsGRVnD3Rx9Fcf4wSQzFFBk4wXoQlqUGAVn\newatsVVR7an7i+jyDrJVXc4IKwubSmod11hwhzmA9dihclUmJwKIhvS7cJEv\nhgr1Pr+hwnCafvkNFDPvwJ08COSPC1bysNHK/0Xn14i6ubUocZdBmcwkxG7W\neBV8\r\n=mHM1\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIF8AFfk3S8gcZ6naAn78nl1BaxFvsWCbvPzOg8lyQiq5AiAPPMUNbhpgxyxOmuCW/Ne0XyB/Rzien4+F0NFCGRqeog=="}]},"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_2.0.3-b_1626897531698_0.8968233029142356"},"_hasShrinkwrap":false},"2.1.0":{"name":"json-server-auth","description":"Authentication middleware for JSON Server","version":"2.1.0","author":{"name":"Jeremy Bensimon"},"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","bin":{"json-server-auth":"dist\\bin.js"},"engines":{"node":">=10"},"engineStrict":true,"scripts":{"build":"rimraf dist && tsc -p tsconfig.build.json","prepublishOnly":"yarn run build","test":"jest","test:file":"jest --testPathPattern","test:watch":"jest --watch --verbose false","release":"standard-version"},"peerDependencies":{"json-server":"*"},"dependencies":{"bcryptjs":"^2.4.3","jsonwebtoken":"^8.5.1","yargs":"^16.2.0"},"devDependencies":{"@types/bcryptjs":"^2.4.2","@types/jest":"^26.0.24","@types/json-server":"^0.14.4","@types/jsonwebtoken":"^8.5.4","@types/supertest":"^2.0.11","@types/yargs":"^16.0.0","jest":"^27.0.6","json-server":"^0.16.3","rimraf":"^3.0.2","standard-version":"^9.3.1","supertest":"^6.1.4","tree-kill":"^1.2.2","ts-jest":"^27.0.4","ts-node-dev":"^1.1.8","tslint":"^6.1.3","tslint-config-prettier":"^1.18.0","typescript":"^4.3.5","typescript-tslint-plugin":"^1.0.1"},"keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"licenseText":"MIT License\n\nCopyright (c) 2018 Jeremy Bensimon\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"json-server-auth@2.1.0","dist":{"shasum":"cd0925c546d0df99e5bac366354d40727e04a151","integrity":"sha512-uf6rud43cH+bfOqA+kqSqdNdVtOj56qJ6nNKH6nAZ8bFxpMY9zzthgK9trrvkVDzihqLfvZ0rwWnGZHACNckGA==","tarball":"https://registry.npmjs.org/json-server-auth/-/json-server-auth-2.1.0.tgz","fileCount":21,"unpackedSize":35878,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJg+IoWCRA9TVsSAnZWagAAnyMP/RmqiRFFVXPwA95Ovo71\n0FahuLWazEiBfsIVB8f+woP1ub4wDpgdE9/vv/eGPhSjNSKHtleUMgSuYgeL\nrzTWNYVfBzz3/WvPdDMeVZHgGPNC5UaoJbbUYdBgu9y51ycmcLheafYGk1WM\nES9WD2EVDPTcNhphHh/DhWHZtfKR2CeEnHb/6p3U7KlDJY5pW/bb9dKRaQDw\nCUX2mC/x4ivdzBbN27eT0TsgwznN1nFG4GRDEYTNnPfllHX553Uku2NrtnH2\nk+tAvE9xN87bEoX9QxbVqVVdB8g3pNY/GD1G/2XxayN0zabI5fafJdHoWwDv\nz87sVZohPC/A0jUgj4Y6EZsYbaI0+1jP9gEr0EMHCkJhHQh8atGeeN/fITns\nqsVrgMNGGDobvmi2ZRd6QnMensJFYb1Kpzqk5f+ma53onsS1Ye7cQ3WPpBPj\n5JL3tEEtDQLtmfq3R5wtgJ41b0vP0R+sWTNF60/kMZgspR9HyAFOOwCD2oKs\nrq9fa+6/eAfpRk6ZSRpAVxO3OWJX6AtF87856LMrOzG3Wg/wsJ9HSwNQHFem\nL4hXscgyON7cFkx3AhboGHfUXaJXpmQ3KGms3j8s0y2ftD4azVKPPREicKs/\nLl1iLgUTBaAhTeqltXy5fKaJ2/jfy/hq5UjuqeEU7U889mzZnc3V467MhlXS\nL87+\r\n=W6Nk\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICI0+xMMRW0vC5JWLXb90SwH95jeW+N5V6glyFCKuiWHAiAtPjFfjFJVGxzcPd/53/fRD/mtwymCJBZ51ZZS+8d6AA=="}]},"_npmUser":{"name":"jeben","email":"bensimon.jeremy@gmail.com"},"directories":{},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/json-server-auth_2.1.0_1626901014255_0.5558170521238905"},"_hasShrinkwrap":false}},"time":{"created":"2018-12-16T23:36:52.638Z","1.0.0":"2018-12-16T23:36:52.801Z","modified":"2022-05-06T22:09:23.931Z","1.1.0":"2018-12-24T00:50:06.511Z","1.2.0":"2019-05-11T18:15:02.234Z","1.2.1":"2019-06-15T18:45:01.722Z","2.0.0":"2020-05-31T23:30:53.788Z","2.0.1":"2020-06-01T14:03:50.404Z","2.0.2":"2020-06-01T20:00:24.498Z","2.0.3":"2021-07-21T19:51:06.870Z","2.0.3-b":"2021-07-21T19:58:51.847Z","2.1.0":"2021-07-21T20:56:54.454Z"},"maintainers":[{"name":"jeben","email":"bensimon.jeremy@gmail.com"}],"description":"Authentication middleware for JSON Server","keywords":["JSON","server","fake","REST","API","prototyping","mock","mocking","test","testing","rest","data","dummy","sandbox","json-server","middleware","auth","authentication","authorization","jwt"],"repository":{"type":"git","url":"https://github.com/jeremyben/json-server-auth.git"},"author":{"name":"Jeremy Bensimon"},"license":"MIT","readme":"# 🔐 JSON Server Auth\n\nJWT authentication middleware for **[JSON Server](https://github.com/typicode/json-server)**\n\nBecause you also need a fake **authentication & authorization flow** for your prototyping.\n\n## Getting started\n\nInstall **both** JSON Server and JSON Server Auth :\n\n```bash\n# NPM\nnpm install -D json-server json-server-auth\n\n# Yarn\nyarn add -D json-server json-server-auth\n```\n\nCreate a `db.json` file with a `users` collection :\n\n```json\n{\n  \"users\": []\n}\n```\n\nStart JSON server (with _JSON server Auth_ as middleware) :\n\n```bash\njson-server db.json -m ./node_modules/json-server-auth\n# with json-server installed globally and json-server-auth installed locally\n```\n\n##### 📢 but wait !\n\nAs a convenience, **`json-server-auth`** CLI exposes `json-server` bundled with its middlewares :\n\n```bash\njson-server-auth db.json\n# with json-server-auth installed globally\n```\n\n_It exposes and works the same for all [JSON Server flags](https://github.com/typicode/json-server#cli-usage)._\n\n## Authentication flow 🔑\n\nJSON Server Auth adds a simple [JWT based](https://jwt.io/) authentication flow.\n\n### Register 👥\n\nAny of the following routes registers a new user :\n\n- **`POST /register`**\n- **`POST /signup`**\n- **`POST /users`**\n\n**`email`** and **`password`** are required in the request body :\n\n```http\nPOST /register\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\"\n}\n```\n\nThe password is encrypted by [bcryptjs](https://github.com/dcodeIO/bcrypt.js).\nThe response contains the JWT access token (expiration time of 1 hour) :\n\n```http\n201 Created\n{\n  \"accessToken\": \"xxx.xxx.xxx\"\n}\n```\n\n###### Other properties\n\nAny other property can be added to the request body without being validated :\n\n```http\nPOST /register\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\",\n  \"firstname\": \"Olivier\",\n  \"lastname\": \"Monge\",\n  \"age\": 32\n}\n```\n\n###### Update\n\nAny update to an existing user (via `PATCH` or `PUT` methods) will go through the same process for `email` and `password`.\n\n### Login 🛂\n\nAny of the following routes logs an existing user in :\n\n- **`POST /login`**\n- **`POST /signin`**\n\n**`email`** and **`password`** are required, of course :\n\n```http\nPOST /login\n{\n  \"email\": \"olivier@mail.com\",\n  \"password\": \"bestPassw0rd\"\n}\n```\n\nThe response contains the JWT access token (expiration time of 1 hour) :\n\n```http\n200 OK\n{\n  \"accessToken\": \"xxx.xxx.xxx\"\n}\n```\n\n#### JWT payload 📇\n\nThe access token has the following claims :\n\n- **`sub` :** the user `id` (as per the [JWT specs](https://tools.ietf.org/html/rfc7519#section-4.1.2)).\n- **`email` :** the user `email`.\n\n## Authorization flow 🛡️\n\nJSON Server Auth provides generic guards as **route middlewares**.\n\nTo handle common use cases, JSON Server Auth draws inspiration from **Unix filesystem permissions**, especialy the [numeric notation](https://en.wikipedia.org/wiki/File_system_permissions#Numeric_notation).\n\n- We add **`4`** for **read** permission.\n- We add **`2`** for **write** permission.\n\n_Of course CRUD is not a filesystem, so we don't add 1 for execute permission._\n\nSimilarly to Unix, we then have three digits to match each user type :\n\n- First digit are the permissions for the **resource owner**.\n- Second digit are the permissions for the **logged-in users**.\n- Third digit are the permissions for the **public users**.\n\nFor example, **`640`** means that only the owner can write the resource, logged-in users can read the resource, and public users cannot access the resource at all.\n\n#### The resource owner 🛀\n\nA user is the owner of a resource if that resource has a **`userId`** property that matches his `id` property. Example:\n\n```js\n// The owner of\n{ id: 8, text: 'blabla', userId: 1 }\n// is\n{ id: 1, email: 'olivier@mail.com' }\n```\n\nPrivate guarded routes will use the JWT `sub` claim (which equals the user `id`) to check if the user actually owns the requested resource, by comparing `sub` with the `userId` property.\n\n_Except for the actual `users` collection, where the JWT `sub` claim must match the `id` property._\n\n### Guarded routes 🚥\n\nGuarded routes exist at the root and can restrict access to any resource you put after them :\n\n|    Route     | Resource permissions                                                                                 |\n| :----------: | :--------------------------------------------------------------------------------------------------- |\n| **`/664/*`** | User must be logged to _write_ the resource. <br> Everyone can _read_ the resource.                  |\n| **`/660/*`** | User must be logged to _write_ or _read_ the resource.                                               |\n| **`/644/*`** | User must own the resource to _write_ the resource. <br> Everyone can _read_ the resource.           |\n| **`/640/*`** | User must own the resource to _write_ the resource. <br> User must be logged to _read_ the resource. |\n| **`/600/*`** | User must own the resource to _write_ or _read_ the resource.                                        |\n| **`/444/*`** | No one can _write_ the resource. <br> Everyone can _read_ the resource.                              |\n| **`/440/*`** | No one can _write_ the resource. <br> User must be logged to _read_ the resource.                    |\n| **`/400/*`** | No one can _write_ the resource. <br> User must own the resource to _read_ the resource.             |\n\n#### Examples\n\n- Public user (not logged-in) does the following requests : \n\n| _Request_                               | _Response_         |\n| :-------------------------------------- | :----------------- |\n| `GET /664/posts`                        | `200 OK`           |\n| `POST /664/posts`<br>`{text: 'blabla'}` | `401 UNAUTHORIZED` |\n\n- Logged-in user with `id: 1` does the following requests :\n\n| _Request_                                                  | _Response_      |\n| :--------------------------------------------------------- | :-------------- |\n| `GET /600/users/1`<br>`Authorization: Bearer xxx.xxx.xxx`  | `200 OK`        |\n| `GET /600/users/23`<br>`Authorization: Bearer xxx.xxx.xxx` | `403 FORBIDDEN` |\n\n### Setup permissions 💡\n\nOf course, you don't want to directly use guarded routes in your requests.\nWe can take advantage of [JSON Server custom routes feature](https://github.com/typicode/json-server#add-custom-routes) to setup resource permissions ahead.\n\nCreate a `routes.json` file :\n\n```json\n{\n  \"/users*\": \"/600/users$1\",\n  \"/messages*\": \"/640/messages$1\"\n}\n```\n\nThen :\n\n```bash\njson-server db.json -m ./node_modules/json-server-auth -r routes.json\n# with json-server installed globally and json-server-auth installed locally\n```\n\n##### 📢 but wait !\n\nAs a convenience, **`json-server-auth`** CLI allows you to define permissions in a more succinct way :\n\n```json\n{\n  \"users\": 600,\n  \"messages\": 640\n}\n```\n\nThen :\n\n```bash\njson-server-auth db.json -r routes.json\n# with json-server-auth installed globally\n```\n\nYou can still add any other _normal_ custom routes :\n\n```json\n{\n  \"users\": 600,\n  \"messages\": 640,\n  \"/posts/:category\": \"/posts?category=:category\"\n}\n```\n\n## Module usage 🔩\n\nIf you go the programmatic way and [use JSON Server as a module](https://github.com/typicode/json-server#module), there is an extra step to properly integrate JSON Server Auth :\n\n⚠️ You must bind the router property `db` to the created app, like the [JSON Server CLI does](https://github.com/typicode/json-server/blob/master/src/cli/run.js#L74), and you must apply the middlewares in a specific order.\n\n```js\nconst jsonServer = require('json-server')\nconst auth = require('json-server-auth')\n\nconst app = jsonServer.create()\nconst router = jsonServer.router('db.json')\n\n// /!\\ Bind the router db to the app\napp.db = router.db\n\n// You must apply the auth middleware before the router\napp.use(auth)\napp.use(router)\napp.listen(3000)\n```\n\n#### Permisssions Rewriter\n\nThe custom rewriter is accessible via a subproperty :\n\n```js\nconst auth = require('json-server-auth')\n\nconst rules = auth.rewriter({\n  // Permission rules\n  users: 600,\n  messages: 640,\n  // Other rules\n  '/posts/:category': '/posts?category=:category',\n})\n\n// You must apply the middlewares in the following order\napp.use(rules)\napp.use(auth)\napp.use(router)\n```\n\n## TODO 📜\n\n- [ ] Use JSON Server `id` and `foreignKeySuffix` parameters\n- [ ] Handle query params in list requests to secure guarded routes more precisely\n- [ ] Allow configuration of :\n  - [ ] Users collection name\n  - [ ] Minimum password length\n  - [ ] JWT expiry time\n  - [ ] JWT property name in response\n- [ ] Implement JWT Refresh Token\n- [ ] Possibility to disable password encryption ?\n","readmeFilename":"README.MD"}