{"_id":"koa-jwt2","_rev":"4-e3f79e071ecc520acb6538f687ba7544","name":"koa-jwt2","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.1":{"name":"koa-jwt2","version":"1.0.1","description":"JWT authentication middleware.","keywords":["auth","authn","authentication","authz","authorization","http","jwt","token","oauth","koa"],"main":"./lib","scripts":{"test":"egg-bin test"},"dependencies":{"async":"^1.5.0","jsonwebtoken":"^8.1.0","koa-unless":"^1.0.7","lodash.isfunction":"^3.0.9","lodash.set":"^4.0.0"},"devDependencies":{"egg-bin":"^4.3.7","conventional-changelog":"~1.1.0","mocha":"1.x.x","koa":"^2.5.0"},"repository":{"type":"git","url":"git://github.com/okoala/koa-jwt2.git"},"bugs":{"url":"http://github.com/okoala/koa-jwt2/issues"},"author":{"name":"okoala","email":"dapixp@gmail.com"},"license":"MIT","engines":{"node":">= 6.0.0"},"gitHead":"a6c89cbb9fc40f3f635193ea873b1d15383c3a59","homepage":"https://github.com/okoala/koa-jwt2#readme","_id":"koa-jwt2@1.0.1","_npmVersion":"5.6.0","_nodeVersion":"8.9.0","_npmUser":{"name":"dapixp","email":"dapixp@gmail.com"},"dist":{"integrity":"sha512-zpFpfIU6P/GlBuLFK5lwzQSP0G8Ixj2XdRskMA17xxYu2iuID0ig1eUYfLYwNGpCcVadV6HwBUQ29exPdbdvaw==","shasum":"51ea9ad2594db408c42fdca76b19cd3505ec576e","tarball":"https://registry.npmjs.org/koa-jwt2/-/koa-jwt2-1.0.1.tgz","fileCount":12,"unpackedSize":29896,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDiqeIbN/FEjfBinVw4c9hr7vqCCDomT2wYDl/3ENepeAIhALnQnmsrWV5imWREFfk+Je2xnZXZDn4QSDw4rcStI3c6"}]},"maintainers":[{"name":"dapixp","email":"dapixp@gmail.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/koa-jwt2_1.0.1_1519886215759_0.14377211381748212"},"_hasShrinkwrap":false},"1.0.2":{"name":"koa-jwt2","version":"1.0.2","description":"JWT authentication middleware.","keywords":["auth","authn","authentication","authz","authorization","http","jwt","token","oauth","koa"],"main":"./lib","scripts":{"test":"egg-bin test"},"dependencies":{"async":"^1.5.0","jsonwebtoken":"^8.1.0","koa-unless":"^1.0.7","lodash.isfunction":"^3.0.9","lodash.set":"^4.0.0"},"devDependencies":{"egg-bin":"^4.3.7","conventional-changelog":"~1.1.0","mocha":"1.x.x","koa":"^2.5.0"},"repository":{"type":"git","url":"git://github.com/okoala/koa-jwt2.git"},"bugs":{"url":"http://github.com/okoala/koa-jwt2/issues"},"author":{"name":"okoala","email":"dapixp@gmail.com"},"license":"MIT","engines":{"node":">= 8.0.0"},"gitHead":"aea570fab5b608828edeff0a9f03aa7575f0f8fb","homepage":"https://github.com/okoala/koa-jwt2#readme","_id":"koa-jwt2@1.0.2","_npmVersion":"5.6.0","_nodeVersion":"8.9.0","_npmUser":{"name":"dapixp","email":"dapixp@gmail.com"},"dist":{"integrity":"sha512-gi3mJT7JHs+Dox2MNgSHnwHg4nnjX4+Zl2yj4gwLTlwD9HEgVzIlNUiC7V4DtDQc9bIgePZWbty40nK0hsLacQ==","shasum":"649e23948f80a7785330a706ac5648163cf849ce","tarball":"https://registry.npmjs.org/koa-jwt2/-/koa-jwt2-1.0.2.tgz","fileCount":12,"unpackedSize":29888,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD8k9X232g6yGrfdZSTfMrk8zDjbBOysT6VsE9cwvWVrwIgISsYqA0QELrsr0aZwS1FAtWBxxqz+joAqOKy5Ct64KU="}]},"maintainers":[{"name":"dapixp","email":"dapixp@gmail.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/koa-jwt2_1.0.2_1519886486395_0.2538439489887856"},"_hasShrinkwrap":false},"1.0.3":{"name":"koa-jwt2","version":"1.0.3","description":"JWT authentication middleware.","keywords":["auth","authn","authentication","authz","authorization","http","jwt","token","oauth","koa"],"main":"./lib","scripts":{"test":"egg-bin test"},"dependencies":{"async":"^1.5.0","jsonwebtoken":"^8.1.0","koa-unless":"^1.0.7","lodash.isfunction":"^3.0.9","lodash.set":"^4.0.0"},"devDependencies":{"egg-bin":"^4.3.7","conventional-changelog":"~1.1.0","mocha":"1.x.x","koa":"^2.5.0"},"repository":{"type":"git","url":"git://github.com/okoala/koa-jwt2.git"},"bugs":{"url":"http://github.com/okoala/koa-jwt2/issues"},"author":{"name":"okoala","email":"dapixp@gmail.com"},"license":"MIT","engines":{"node":">= 8.0.0"},"gitHead":"5b0dc884222048fe0a5710024e5cddc1a2d16d00","homepage":"https://github.com/okoala/koa-jwt2#readme","_id":"koa-jwt2@1.0.3","_npmVersion":"5.6.0","_nodeVersion":"8.9.0","_npmUser":{"name":"dapixp","email":"dapixp@gmail.com"},"dist":{"integrity":"sha512-ACW/sQ21vlkR/HBXnGvJfM2yDkKnv1GZe6/1nro+Mt4+bWhJq007esu2h9oZcj2+nce47PXcan2rXVaKmX295w==","shasum":"a80309800d0bb2c0f957b8b2cecc2cae0444f219","tarball":"https://registry.npmjs.org/koa-jwt2/-/koa-jwt2-1.0.3.tgz","fileCount":12,"unpackedSize":29823,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCea36WOtZiV2+szziS1TdewYhk/w0wtyC9P3rMnb/OOwIgEJQQZNBzlamYddOB0jrUzTny+kIRt0CZnjALrCiwEDU="}]},"maintainers":[{"name":"dapixp","email":"dapixp@gmail.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/koa-jwt2_1.0.3_1519893848546_0.6670712990124694"},"_hasShrinkwrap":false}},"time":{"created":"2018-03-01T06:36:55.759Z","1.0.1":"2018-03-01T06:36:55.837Z","modified":"2022-05-07T09:59:50.008Z","1.0.2":"2018-03-01T06:41:26.491Z","1.0.3":"2018-03-01T08:44:08.646Z"},"maintainers":[{"name":"dapixp","email":"dapixp@gmail.com"}],"description":"JWT authentication middleware.","homepage":"https://github.com/okoala/koa-jwt2#readme","keywords":["auth","authn","authentication","authz","authorization","http","jwt","token","oauth","koa"],"repository":{"type":"git","url":"git://github.com/okoala/koa-jwt2.git"},"author":{"name":"okoala","email":"dapixp@gmail.com"},"bugs":{"url":"http://github.com/okoala/koa-jwt2/issues"},"license":"MIT","readme":"# koa-jwt2\n\n[![Build](https://travis-ci.org/okoala/koa-jwt2.png)](http://travis-ci.org/okoala/koa-jwt2)\n\nKoa middleware that validates JsonWebTokens and sets `ctx.state.user`.\n\nThis module lets you authenticate HTTP requests using JWT tokens in your Node.js\napplications. JWTs are typically used to protect API endpoints, and are\noften issued using OpenID Connect.\n\n## Install\n\n    $ npm install koa-jwt2 --save\n\n## Usage\n\nThe JWT authentication middleware authenticates callers using a JWT.\nIf the token is valid, `ctx.state.user` will be set with the JSON object decoded\nto be used by later middleware for authorization and access control.\n\nFor example,\n\n```javascript\nvar jwt = require(\"koa-jwt2\");\n\napp.get(\"/protected\", jwt({ secret: \"shhhhhhared-secret\" }), async function(\n  ctx\n) {\n  if (!ctx.state.user.admin) return (ctx.status = 401);\n  ctx.status = 200;\n});\n```\n\nYou can specify audience and/or issuer as well:\n\n```javascript\njwt({\n  secret: \"shhhhhhared-secret\",\n  audience: \"http://myapi/protected\",\n  issuer: \"http://issuer\"\n});\n```\n\n> If the JWT has an expiration (`exp`), it will be checked.\n\nIf you are using a base64 URL-encoded secret, pass a `Buffer` with `base64` encoding as the secret instead of a string:\n\n```javascript\njwt({ secret: new Buffer(\"shhhhhhared-secret\", \"base64\") });\n```\n\nOptionally you can make some paths unprotected as follows:\n\n```javascript\napp.use(jwt({ secret: \"shhhhhhared-secret\" }).unless({ path: [\"/token\"] }));\n```\n\nThis is especially useful when applying to multiple routes. In the example above, `path` can be a string, a regexp, or an array of any of those.\n\n> For more details on the `.unless` syntax including additional options, please see [koa-unless](https://github.com/Foxandxss/koa-unless).\n\nThis module also support tokens signed with public/private key pairs. Instead of a secret, you can specify a Buffer with the public key\n\n```javascript\nvar publicKey = fs.readFileSync(\"/path/to/public.pub\");\njwt({ secret: publicKey });\n```\n\nBy default, the decoded token is attached to `ctx.state.user` but can be configured with the `property` option.\n\n```javascript\njwt({ secret: publicKey, property: \"auth\" });\n```\n\nA custom function for extracting the token from a request can be specified with\nthe `getToken` option. This is useful if you need to pass the token through a\nquery parameter or a cookie. You can throw an error in this function and it will\nbe handled by `koa-jwt2`.\n\n```javascript\napp.use(\n  jwt({\n    secret: \"hello world !\",\n    credentialsRequired: false,\n    getToken: function fromHeaderOrQuerystring(ctx) {\n      if (\n        ctx.headers.authorization &&\n        ctx.headers.authorization.split(\" \")[0] === \"Bearer\"\n      ) {\n        return ctx.headers.authorization.split(\" \")[1];\n      } else if (ctx.query && ctx.query.token) {\n        return ctx.query.token;\n      }\n      return null;\n    }\n  })\n);\n```\n\n### Multi-tenancy\n\nIf you are developing an application in which the secret used to sign tokens is not static, you can provide a async function as the `secret` parameter. The function has the signature: `async function(ctx, payload)`:\n\n* `ctx` (`Object`) - The koa `ctx` object.\n* `payload` (`Object`) - An object with the JWT claims.\n\nneed to return a secret string or promise to use to verify the JWT.\n\nFor example, if the secret varies based on the [JWT issuer](http://self-issued.info/docs/draft-ietf-oauth-json-web-token.html#issDef):\n\n```javascript\nconst jwt = require(\"koa-jwt2\");\nconst data = require(\"./data\");\nconst utilities = require(\"./utilities\");\n\nconst secretAsync = async function(ctx, payload) {\n  const issuer = payload.iss;\n\n  return new Promise((resolve, reject) => {\n    data.getTenantByIdentifier(issuer, function(err, tenant) {\n      if (err) {\n        return reject(err);\n      }\n      if (!tenant) {\n        reject(new Error(\"missing_secret\"));\n      }\n\n      const secret = utilities.decrypt(tenant.secret);\n      resolve(secret);\n    });\n  });\n};\n\napp.get(\"/protected\", jwt({ secret: secretCallback }), async function(ctx) {\n  if (!ctx.state.user.admin) {\n    ctx.throw(401);\n  }\n  ctx.status = 200;\n  ctx.body = \"\";\n});\n```\n\n### Revoked tokens\n\nIt is possible that some tokens will need to be revoked so they cannot be used any longer. You can provide a function as the `isRevoked` option. The signature of the function is `async function(ctx, payload)`:\n\n* `ctx` (`Object`) - The koa `context` object.\n* `payload` (`Object`) - An object with the JWT claims.\n\nFor example, if the `(iss, jti)` claim pair is used to identify a JWT:\n\n```javascript\nconst jwt = require(\"koa-jwt2\");\nconst data = require(\"./data\");\nconst utilities = require(\"./utilities\");\n\nconst isRevokedAsync = function(req, payload, done) {\n  const issuer = payload.iss;\n  const tokenId = payload.jti;\n\n  return new Promise((resolve, reject) => {\n    data.getRevokedToken(issuer, tokenId, function(err, token) {\n      if (err) {\n        return reject(err);\n      }\n      resolve(!!token);\n    });\n  });\n};\n\napp.get(\n  \"/protected\",\n  jwt({\n    secret: \"shhhhhhared-secret\",\n    isRevoked: isRevokedAsync\n  }),\n  async function(ctx) {\n    if (!ctx.state.user.admin) {\n      ctx.throw(401);\n    }\n    ctx.status = 200;\n    ctx.body = \"\";\n  }\n);\n```\n\n### Error handling\n\nThe default behavior is to throw an error when the token is invalid, so you can add your custom logic to manage unauthorized access as follows:\n\n```javascript\napp.use(async function(ctx, next) {\n  try {\n    await next();\n  } catch (err) {\n    if (err.name === \"UnauthorizedError\") {\n      ctx.status = 401;\n      ctx.body = \"invalid token...\";\n    }\n  }\n});\n```\n\nYou might want to use this module to identify registered users while still providing access to unregistered users. You\ncan do this by using the option _credentialsRequired_:\n\n```javascript\napp.use(\n  jwt({\n    secret: \"hello world !\",\n    credentialsRequired: false\n  })\n);\n```\n\n## Related Modules\n\n* [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken) — JSON Web Token sign and verification\n\n## Tests\n\n    $ npm install\n    $ npm test\n\n## Contributors\n\nCheck them out [here](https://github.com/okoala/koa-jwt2/graphs/contributors)\n\n## License\n\nThis project is licensed under the MIT license. See the [LICENSE](LICENSE) file for more info.\n","readmeFilename":"README.md"}