{"_id":"oauth2orize-koa","_rev":"10-ecffbefd83e5962da1cdc17f4165a6eb","name":"oauth2orize-koa","description":"OAuth 2.0 authorization server toolkit for Node.js.","dist-tags":{"latest":"1.3.2"},"versions":{"1.2.0":{"name":"oauth2orize-koa","version":"1.2.0","description":"OAuth 2.0 authorization server toolkit for Node.js.","keywords":["oauth","oauth2","auth","authz","authorization","passport","middleware","koa"],"author":{"name":"James Sharp","email":"james@ortootech.com"},"repository":{"type":"git","url":"git://github.com/ortoo/oauth2orize.git"},"bugs":{"url":"http://github.com/ortoo/oauth2orize/issues"},"licenses":[{"type":"MIT","url":"http://www.opensource.org/licenses/MIT"}],"main":"./lib","dependencies":{"debug":"2.x.x","koa-compose":"^3.0.0","uid2":"0.0.x","utils-merge":"1.x.x"},"devDependencies":{"babel-eslint":"^4.1.6","babel-preset-stage-3":"^6.3.13","babel-register":"^6.4.3","chai":"1.x.x","eslint":"^1.10.3","mocha":"2.x.x"},"engines":{"node":">= 0.4.0"},"scripts":{"test":"mocha --reporter spec --require test/bootstrap/node test/*.test.js test/**/*.test.js"},"gitHead":"57995cd62a4a08f66d7d22e5615ebc2de3752a18","homepage":"https://github.com/ortoo/oauth2orize#readme","_id":"oauth2orize-koa@1.2.0","_shasum":"3c6891ff7c67066a1f2cc12d559968c1a0d882f9","_from":".","_npmVersion":"3.3.12","_nodeVersion":"5.4.0","_npmUser":{"name":"ortoo","email":"james@ortootech.com"},"dist":{"shasum":"3c6891ff7c67066a1f2cc12d559968c1a0d882f9","tarball":"https://registry.npmjs.org/oauth2orize-koa/-/oauth2orize-koa-1.2.0.tgz","integrity":"sha512-3D+lwDo1AR3upYFIlGKFvXn1om1P8ISSA6DXrV+Rcb63x9T1gexqO8e5cBz6L307eCsCRXLV56XawcvWkhAkyQ==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD+KAHt9xYyOtbHlgPIAahOx9jY42n0ytKxX/ndelViFQIgHcvAEQDnTvYMehn5GuIbubI5DbeijLDhbB7NMz1ZuTA="}]},"maintainers":[{"name":"ortoo","email":"james@ortootech.com"}],"directories":{}},"1.2.1":{"name":"oauth2orize-koa","version":"1.2.1","description":"OAuth 2.0 authorization server toolkit for Node.js.","keywords":["oauth","oauth2","auth","authz","authorization","passport","middleware","koa"],"author":{"name":"James Sharp","email":"james@ortootech.com"},"repository":{"type":"git","url":"git://github.com/ortoo/oauth2orize.git"},"bugs":{"url":"http://github.com/ortoo/oauth2orize/issues"},"licenses":[{"type":"MIT","url":"http://www.opensource.org/licenses/MIT"}],"main":"./lib","dependencies":{"debug":"2.x.x","koa-compose":"^3.0.0","uid2":"0.0.x","utils-merge":"1.x.x"},"devDependencies":{"babel-cli":"^6.4.5","babel-eslint":"^4.1.6","babel-preset-stage-3":"^6.3.13","babel-register":"^6.4.3","chai":"1.x.x","eslint":"^1.10.3","mocha":"2.x.x"},"engines":{"node":">= 0.4.0"},"scripts":{"version":"babel src --out-dir lib","postversion":"git push && git push --tags","pretest":"babel src --out-dir lib","test":"mocha --reporter spec --require test/bootstrap/node test/*.test.js test/**/*.test.js"},"gitHead":"9493dd6e1b9ff49faefc4b21383fba10eb8db2f8","homepage":"https://github.com/ortoo/oauth2orize#readme","_id":"oauth2orize-koa@1.2.1","_shasum":"76ca7154e1ce669f39b03a7cf04ff311fd7cecd6","_from":".","_npmVersion":"3.3.12","_nodeVersion":"5.4.0","_npmUser":{"name":"ortoo","email":"james@ortootech.com"},"dist":{"shasum":"76ca7154e1ce669f39b03a7cf04ff311fd7cecd6","tarball":"https://registry.npmjs.org/oauth2orize-koa/-/oauth2orize-koa-1.2.1.tgz","integrity":"sha512-yL3DT71Rl2QiCU8+MwAC7fINoe2AVtmx1HmkclsWFDRySDYAJwZ1RD7uS9CWk9PlaZNmtPR7t4kW0YUgAFqFZA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEDNJA4D+1fRjpNGNSpv2lmhWClPlxgnikEM2w4uRLnxAiEAveumT9B6R9BAj+eKymYZGQ5qc5SZFgUtItbPZ7jU+HM="}]},"maintainers":[{"name":"ortoo","email":"james@ortootech.com"}],"directories":{}},"1.3.0":{"name":"oauth2orize-koa","version":"1.3.0","description":"OAuth 2.0 authorization server toolkit for Node.js.","keywords":["oauth","oauth2","auth","authz","authorization","passport","middleware","koa"],"author":{"name":"James Sharp","email":"james@ortootech.com"},"repository":{"type":"git","url":"git://github.com/ortoo/oauth2orize.git"},"bugs":{"url":"http://github.com/ortoo/oauth2orize/issues"},"licenses":[{"type":"MIT","url":"http://www.opensource.org/licenses/MIT"}],"main":"./lib","dependencies":{"debug":"2.x.x","koa-compose":"^3.0.0","uid2":"0.0.x","utils-merge":"1.x.x"},"devDependencies":{"babel-cli":"^6.4.5","babel-eslint":"^4.1.6","babel-preset-es2015-node5":"^1.1.1","babel-preset-stage-3":"^6.3.13","babel-register":"^6.4.3","chai":"1.x.x","eslint":"^1.10.3","mocha":"2.x.x"},"engines":{"node":">= 0.4.0"},"scripts":{"version":"babel src --out-dir lib","postversion":"git push && git push --tags","pretest":"babel src --out-dir lib","test":"mocha --reporter spec --require test/bootstrap/node test/*.test.js test/**/*.test.js"},"gitHead":"b78e945664bd6b2f10f632801d4da3b02a455091","homepage":"https://github.com/ortoo/oauth2orize#readme","_id":"oauth2orize-koa@1.3.0","_shasum":"fb5c4a1cae6a5f4977dd9f27d9fcb0ec55a2b4f9","_from":".","_npmVersion":"3.3.12","_nodeVersion":"5.4.0","_npmUser":{"name":"ortoo","email":"james@ortootech.com"},"dist":{"shasum":"fb5c4a1cae6a5f4977dd9f27d9fcb0ec55a2b4f9","tarball":"https://registry.npmjs.org/oauth2orize-koa/-/oauth2orize-koa-1.3.0.tgz","integrity":"sha512-FYM0Q4tnuAXYO0XTx0vtqNIUicJ59bPBZ47pWNIIyipSx3W7t1wuh6LK0Ixk3+MUhonVSmdTpU1OeAv4Rnv+LQ==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC0SACfat95piAIQdmJaxhi1Y1gty+5CN8mIgbr81Ek3gIhAK+o6pIvyWGZeh5H/4SySxjv3om2VIFqVHDtjsWTFdys"}]},"maintainers":[{"name":"ortoo","email":"james@ortootech.com"}],"directories":{}},"1.3.1":{"name":"oauth2orize-koa","version":"1.3.1","description":"OAuth 2.0 authorization server toolkit for Node.js.","keywords":["oauth","oauth2","auth","authz","authorization","passport","middleware","koa"],"author":{"name":"James Sharp","email":"james@ortootech.com"},"repository":{"type":"git","url":"git://github.com/ortoo/oauth2orize.git"},"bugs":{"url":"http://github.com/ortoo/oauth2orize/issues"},"licenses":[{"type":"MIT","url":"http://www.opensource.org/licenses/MIT"}],"main":"./lib","dependencies":{"debug":"2.x.x","koa-compose":"^3.0.0","uid2":"0.0.x","utils-merge":"1.x.x"},"devDependencies":{"babel-cli":"^6.4.5","babel-eslint":"^4.1.6","babel-preset-es2015-node5":"^1.1.1","babel-preset-stage-3":"^6.3.13","babel-register":"^6.4.3","chai":"1.x.x","eslint":"^1.10.3","mocha":"2.x.x"},"engines":{"node":">= 0.4.0"},"scripts":{"version":"babel src --out-dir lib","postversion":"git push && git push --tags","pretest":"babel src --out-dir lib","test":"mocha --reporter spec --require test/bootstrap/node test/*.test.js test/**/*.test.js"},"gitHead":"29619ed67d5a7e0a3793c435cc78543b559687c4","homepage":"https://github.com/ortoo/oauth2orize#readme","_id":"oauth2orize-koa@1.3.1","_shasum":"11dbd17a1d7a05aae261410ff2e16e0051b630e3","_from":".","_npmVersion":"3.3.12","_nodeVersion":"5.4.0","_npmUser":{"name":"ortoo","email":"james@ortootech.com"},"dist":{"shasum":"11dbd17a1d7a05aae261410ff2e16e0051b630e3","tarball":"https://registry.npmjs.org/oauth2orize-koa/-/oauth2orize-koa-1.3.1.tgz","integrity":"sha512-sKo4k59nFobkpHg/0UINGmB2nSS7iH5PNEBXVvc3G13wLhlaZgv5a6BARg+vt5nclOfs4a+iQOMF1AVZ5l2/nA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEWwU86DQ5CAjZp/AjfEapuF1GDRkTU5mIIgZbb6l4I1AiBK7iPH82+doXEH7a1MakEYYUr4/x/bqUk+qtfOxqfQQQ=="}]},"maintainers":[{"name":"ortoo","email":"james@ortootech.com"}],"directories":{}},"1.3.2":{"name":"oauth2orize-koa","version":"1.3.2","description":"OAuth 2.0 authorization server toolkit for Node.js.","keywords":["oauth","oauth2","auth","authz","authorization","passport","middleware","koa"],"author":{"name":"James Sharp","email":"james@ortootech.com"},"repository":{"type":"git","url":"git://github.com/ortoo/oauth2orize.git"},"bugs":{"url":"http://github.com/ortoo/oauth2orize/issues"},"licenses":[{"type":"MIT","url":"http://www.opensource.org/licenses/MIT"}],"main":"./lib","dependencies":{"debug":"2.x.x","koa-compose":"^3.0.0","uid2":"0.0.x","utils-merge":"1.x.x"},"devDependencies":{"babel-cli":"^6.4.5","babel-eslint":"^4.1.6","babel-preset-es2015-node5":"^1.1.1","babel-preset-stage-3":"^6.3.13","babel-register":"^6.4.3","chai":"1.x.x","eslint":"^1.10.3","mocha":"2.x.x"},"engines":{"node":">= 0.4.0"},"scripts":{"version":"babel src --out-dir lib","postversion":"git push && git push --tags","pretest":"babel src --out-dir lib","test":"mocha --reporter spec --require test/bootstrap/node test/*.test.js test/**/*.test.js"},"gitHead":"ab728c2927b03fade6255e79cf6bdb30dd195d28","homepage":"https://github.com/ortoo/oauth2orize#readme","_id":"oauth2orize-koa@1.3.2","_shasum":"d587d7fe76cffc5fec7c0d61e00ad8377b19b25d","_from":".","_npmVersion":"3.3.12","_nodeVersion":"5.4.0","_npmUser":{"name":"ortoo","email":"james@ortootech.com"},"dist":{"shasum":"d587d7fe76cffc5fec7c0d61e00ad8377b19b25d","tarball":"https://registry.npmjs.org/oauth2orize-koa/-/oauth2orize-koa-1.3.2.tgz","integrity":"sha512-WX+51ru1GJTYjIVW9sniPpyB+w5vimkOo5xw/2UIt5kMU55P0YFTDITXPyKHyBAu35ag2YYdrjWPYPgL/GWlhQ==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD3E8iy5EK6b26We1AIQ5m2svRMPt2GzNnytiG09mFeEAIga/BXrItjvkyOlftZq3W1i4T5vpioQOZk71iHLju7LLg="}]},"maintainers":[{"name":"ortoo","email":"james@ortootech.com"}],"directories":{}}},"readme":"# OAuth2orize-koa\n\n[![Build](https://travis-ci.org/ortoo/oauth2orize.svg?branch=master)](https://travis-ci.org/ortoo/oauth2orize)\n[![Coverage](https://coveralls.io/repos/ortoo/oauth2orize/badge.svg?branch=master)](https://coveralls.io/r/ortoo/oauth2orize)\n[![Quality](https://codeclimate.com/github/ortoo/oauth2orize/badges/gpa.svg)](https://codeclimate.com/github/ortoo/oauth2orize)\n[![Dependencies](https://david-dm.org/ortoo/oauth2orize.svg)](https://david-dm.org/ortoo/oauth2orize)\n[![Tips](https://img.shields.io/gratipay/jaredhanson.svg)](https://gratipay.com/jaredhanson/)\n\nThis is a complete koa port of [OAuth2orize](https://github.com/jaredhanson/oauth2orize).\nOAuth2orize is an authorization server toolkit for Node.js.  It provides a suite\nof [koa v2](https://github.com/koajs/koa) middleware that can be used\nto assemble a server that implements the [OAuth 2.0](http://tools.ietf.org/html/rfc6749)\nprotocol.\n\n## Install\n\n    $ npm install oauth2orize-koa\n\n## Usage\n\nOAuth 2.0 defines an authorization framework, allowing an extensible set of\nauthorization grants to be exchanged for access tokens.  Implementations are\nfree to choose what grant types to support, by using bundled middleware to\nsupport common types or plugins to support extension types.\n\n#### Create an OAuth Server\n\nCall `createServer()` to create a new OAuth 2.0 server.  This instance exposes\nmiddleware that will be mounted in routes, as well as configuration options.\n\n    var server = oauth2orize.createServer();\n\n#### Register Grants\n\nA client must obtain permission from a user before it is issued an access token.\nThis permission is known as a grant, the most common type of which is an\nauthorization code.\n\n    server.grant(oauth2orize.grant.code(async function(client, redirectURI, user, ares) {\n      var code = utils.uid(16);\n\n      var ac = new AuthorizationCode(code, client.id, redirectURI, user.id, ares.scope);\n      await ac.save();\n      return code;\n    }));\n\nOAuth2orize also bundles support for implicit token grants.\n\n#### Register Exchanges\n\nAfter a client has obtained an authorization grant from the user, that grant can\nbe exchanged for an access token.\n\n    server.exchange(oauth2orize.exchange.code(async function(client, code, redirectURI) {\n      code = await AuthorizationCode.findOne(code);\n      if (client.id !== code.clientId) { return false; }\n      if (redirectURI !== code.redirectUri) { return false; }\n\n      var token = utils.uid(256);\n      var at = new AccessToken(token, code.userId, code.clientId, code.scope);\n      await at.save();\n      return token;\n    }));\n\nOAuth2orize also bundles support for password and client credential grants.\nAdditionally, bundled refresh token support allows expired access tokens to be\nrenewed.\n\n#### Implement Authorization Endpoint\n\nWhen a client requests authorization, it will redirect the user to an\nauthorization endpoint.  The server must authenticate the user and obtain\ntheir permission.\n\n    router.get('/dialog/authorize',\n      login.ensureLoggedIn(),\n      server.authorize(async function(clientID, redirectURI) {\n        var client = await Clients.findOne(clientID);\n        if (!client) { return false; }\n        if (!client.redirectUri != redirectURI) { return false; }\n        return [client, client.redirectURI];\n      }),\n      function(ctx) {\n        res.render('dialog', { transactionID: ctx.state.oauth2.transactionID,\n                               user: ctx.state.user, client: ctx.state.oauth2.client });\n      });\n\nIn this example, [connect-ensure-login](https://github.com/jaredhanson/connect-ensure-login)\nmiddleware is being used to make sure a user is authenticated before\nauthorization proceeds.  At that point, the application renders a dialog\nasking the user to grant access.  The resulting form submission is processed\nusing `decision` middleware.\n\n     router.post('/dialog/authorize/decision',\n       login.ensureLoggedIn(),\n       server.decision());\n\nBased on the grant type requested by the client, the appropriate grant\nmodule registered above will be invoked to issue an authorization code.\n\n#### Session Serialization\n\nObtaining the user's authorization involves multiple request/response pairs.\nDuring this time, an OAuth 2.0 transaction will be serialized to the session.\nClient serialization functions are registered to customize this process, which\nwill typically be as simple as serializing the client ID, and finding the client\nby ID when deserializing.\n\n    server.serializeClient(function(client) {\n      return client.id;\n    });\n\n    server.deserializeClient(async function(id) {\n      var client = await Clients.findOne(id);\n      return client;\n    });\n\n#### Implement Token Endpoint\n\nOnce a user has approved access, the authorization grant can be exchanged by the\nclient for an access token.\n\n    router.post('/token',\n      passport.authenticate(['basic', 'oauth2-client-password'], { session: false }),\n      server.token(),\n      server.errorHandler());\n\n[Passport](http://passportjs.org/) strategies are used to authenticate the\nclient, in this case using either an HTTP Basic authentication header (as\nprovided by [passport-http](https://github.com/jaredhanson/passport-http)) or\nclient credentials in the request body (as provided by\n[passport-oauth2-client-password](https://github.com/jaredhanson/passport-oauth2-client-password)).\n\nBased on the grant type issued to the client, the appropriate exchange module\nregistered above will be invoked to issue an access token.  If an error occurs,\n`errorHandler` middleware will format an error response.\n\n#### Implement API Endpoints\n\nOnce an access token has been issued, a client will use it to make API requests\non behalf of the user.\n\n    router.get('/api/userinfo',\n      passport.authenticate('bearer', { session: false }),\n      function(ctx) {\n        ctx.body = req.user;\n      });\n\nIn this example, bearer tokens are issued, which are then authenticated using\nan HTTP Bearer authentication header (as provided by [passport-http-bearer](https://github.com/jaredhanson/passport-http-bearer))\n\n## Examples\n\nThis [example](https://github.com/ortoo/oauth2orize/tree/master/examples/express2) demonstrates\nhow to implement an OAuth service provider, complete with protected API access.\n\n## Related Modules\n\n- [oauth2orize-openid](https://github.com/ortoo/oauth2orize-openid) — Extensions to support OpenID Connect\n\n## Tests\n\n    $ npm install\n    $ npm test\n\n## Debugging\n\noauth2orize uses the [debug module](https://www.npmjs.org/package/debug).  You can enable debugging messages on the console by doing ```export DEBUG=oauth2orize``` before running your application.\n\n## Credits\n\n  - [Jared Hanson](http://github.com/jaredhanson)\n\n## License\n\n[The MIT License](http://opensource.org/licenses/MIT)\n\nCopyright (c) 2012-2015 Jared Hanson <[http://jaredhanson.net/](http://jaredhanson.net/)>\n","maintainers":[{"email":"james@ortootech.com","name":"ortootech"}],"time":{"modified":"2022-06-22T15:45:53.438Z","created":"2016-01-20T16:53:10.442Z","1.2.0":"2016-01-20T16:53:10.442Z","1.2.1":"2016-01-20T18:31:22.593Z","1.3.0":"2016-01-20T21:30:39.307Z","1.3.1":"2016-01-21T21:03:36.317Z","1.3.2":"2016-01-21T21:24:54.109Z"},"homepage":"https://github.com/ortoo/oauth2orize#readme","keywords":["oauth","oauth2","auth","authz","authorization","passport","middleware","koa"],"repository":{"type":"git","url":"git://github.com/ortoo/oauth2orize.git"},"author":{"name":"James Sharp","email":"james@ortootech.com"},"bugs":{"url":"http://github.com/ortoo/oauth2orize/issues"},"readmeFilename":"README.md"}