{"_id":"secure-ng-resource","_rev":"44-a158d012c267f6c00d259468139b6c67","name":"secure-ng-resource","time":{"modified":"2022-06-26T17:14:04.318Z","created":"2014-03-31T15:43:44.754Z","0.3.9":"2014-03-31T15:45:43.051Z","0.3.10":"2014-03-31T17:19:41.035Z","0.4.0":"2014-04-14T17:20:39.563Z","0.5.1":"2014-07-22T17:00:40.415Z"},"maintainers":[{"name":"davidmikesimon","email":"dsimon@americancouncils.org"}],"description":"[![Build Status](https://travis-ci.org/AmericanCouncils/secure-ng-resource.png?branch=master)](https://travis-ci.org/AmericanCouncils/secure-ng-resource)","readme":"# secure-ng-resource\n\n[![Build Status](https://travis-ci.org/AmericanCouncils/secure-ng-resource.png?branch=master)](https://travis-ci.org/AmericanCouncils/secure-ng-resource)\n\nA wrapper around ngResource that adds authentication to requests, automatically\nasking the user for credentials when needed. Currently supports OAuth password\nflow, and OpenID verification with an Authorization header to pass the key.\n\nThe `ArrayBuffer` javascript type is required; for IE versions 9 and below,\nyou will need to provide a polyfill for it.\n\n## Installation\n\nAfter you've downloaded the secure-ng-resource component with bower, add the\nusual lines in app.js (to `secureNgResource`) and index.html (to\n`components/secure-ng-resource/build/secure-ng-resource.js`).\n\n## Using OAuth password flow\n\nSuppose you are writing an Angular app that is backed by a RESTful web\nservice available at `https://example.com/`. Its authentication is based on the\n[OAuth Resource Owner Password Flow](http://techblog.hybris.com/2012/06/11/oauth2-resource-owner-password-flow/).\nConfigure your app to use this auth system in a session\nservice for your application:\n```js\n// app/scripts/services/appSession.js\n\nangular.module('myApp').factory('appSession', [\n'authSession', 'passwordOAuth', // These are from secureNgResource\nfunction(authSession, passwordOAuth) {\n    return authSession(passwordOAuth(\n        \"https://example.com\", // Host which provides the OAuth tokens\n        \"1_myappmyappmyapp\", // OAuth Client ID\n        \"shhhhhhhhhhhhhhhh\" // OAuth Client Secret\n    ));\n]);\n```\n\nThen you can use this session with secureResource, which is just a wrapper around\n[ngResource](http://docs.angularjs.org/api/ngResource.$resource):\n```js\n// app/scripts/controllers/things.js\n\nangular.module('myApp').controller('ThingsCtrl', [\n'$scope', 'secureResource', 'appSession',\nfunction($scope, secureResource, appSession) {\n    var Thing = secureResource(\n        appSession,\n        'https://example.com/thing/:thingId'\n    );\n\n    $scope.things = Thing.query();\n}]);\n```\nWhen `Thing.query()` executes, SecureResource will add the appropriate\nauthorization to the request. If the request is refused (if the user hasn't\nlogged in yet, or if they logged in a long while ago and their access\ntoken expired), then the user is redirected to your login page (by default\nat `/login`) within your angular app's internal routing system.\n\nYour login controller can interact with the session like so:\n```js\n// app/scripts/controllers/login.js\n\nangular.module('myApp').controller('LoginCtrl', [\n'$scope', 'appSession',\nfunction($scope, appSession) {\n    $scope.credentials = {\n        user: null, // Attach your login username element to this\n        pass: null  // And your password element to this\n    };\n\n    // Have your \"Log In\" button call this\n    $scope.login = function () {\n        if (!$scope.loginForm.$valid) { return; }\n        appSession.login($scope.credentials)\n        .then(null, function(result) {\n            if (result.status == 'denied') {\n                alert(\"Login failed: \" + result.msg);\n            } else {\n                alert(\"Something went wrong: \" + result.msg);\n            }\n        });\n    };\n}]);\n```\n\nYou don't have to worry about redirecting the user after they successfully\nlog in, the `appSession.login` function will take care of that. If the user\nwas at another internal route and got kicked over to the login page by an\nauth failure, then they will be sent back there. Otherwise they will be sent\nto the `/` internal route by default.\n\n## Using OpenID\n\nThe OpenID system requires more specific behavior from the back-end server\nthan the OAuth system. When creating the OpenID auth instance, you supply\na `host` which is typically your server, and a `beginPath` at that host.\n\nThe login process goes like so:\n\n1. The user supplies an OpenID identifier as their credentials. You\n   should pass this identifier URL to AuthSession.login() in an object\n   under the key 'openid_identifier'.\n\n2. Secure-ng-resource redirects user to `beginPath` via a POST, submitting\n   the usual OpenID form data plus these additional fields:\n\n   * key: A random byte string, base64 encoded.\n   * target_url: A URL to go to after authentication completes, generally this\n                 is the URL for the angular app's login page.\n\n3. The server responds with a redirect to the identity provider login page.\n\n4. When authentication completes, the server redirects to the target\n   URL from step #2, with the following JSON structure base64 encoded as\n   the GET argument `auth_resp`:\n\n   * approved: A boolean indicating whether authentication was accepted\n   * sessionId: (If approved) An authentication token, XOR'd against the key\n                and then itself base64 encoded\n   * user: (If approved) The username that the user logged in as\n   * message: (Optional) An explanation of what happened during authentication\n\n5. Assuming access was allowed, then from that point forward any\n   requests that go through secureNgResource using this\n   authentication session will include an `Authorization` header of the\n   form `SesID 123ABC` where `123ABC` is the sessionId from the response\n   object. Note that cookies are *not* used in these requests; this helps\n   to prevent XSS attacks.\n\nIn order to support step #4 of this process, your login controller should check\nfor the `auth_resp` value and pass it to the `login` method if it's present:\n\n```js\nif ($location.search().auth_resp) {\n    appSession.login({auth_resp: $location.search().auth_resp});\n    $location.search('auth_resp', null);\n}\n```\n\n## Credits\n\nProject directory structure and build/test configs based on those found in\n[ng-grid](https://github.com/angular-ui/ng-grid).\n","versions":{"0.3.10":{"name":"secure-ng-resource","version":"0.3.10","author":{"name":"American Councils"},"repository":{"type":"git","url":"https://github.com/AmericanCouncils/secure-ng-resource.git"},"main":"build/secure-ng-resource.min.js","dependencies":{"angular":"1.2.x"},"devDependencies":{"jasmine-node":"1.2.0"},"description":"[![Build Status](https://travis-ci.org/AmericanCouncils/secure-ng-resource.png?branch=master)](https://travis-ci.org/AmericanCouncils/secure-ng-resource)","bugs":{"url":"https://github.com/AmericanCouncils/secure-ng-resource/issues"},"_id":"secure-ng-resource@0.3.10","dist":{"shasum":"3563cfca2069396da3371a8c31bb64b509b337d2","tarball":"https://registry.npmjs.org/secure-ng-resource/-/secure-ng-resource-0.3.10.tgz","integrity":"sha512-Nfin61U+zqGw9dPt30B7MYsxLjxJUxRgP+h2JLKKBIRTK+YCNDF+z/Vd0RDUmp5apZnEq4qZqkICH+ucr5/cRQ==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD03h1jyP8f8PsBgO4ZLwW7UcDyJxwZwjPPUDjPmNGYYAIgQ9lB9ItpLdJZevs8GpC3QZ6HOah0hgCwoWmBLgBvIbk="}]},"_from":".","_npmVersion":"1.3.11","_npmUser":{"name":"davidmikesimon","email":"dsimon@americancouncils.org"},"maintainers":[{"name":"davidmikesimon","email":"dsimon@americancouncils.org"}]},"0.4.0":{"name":"secure-ng-resource","version":"0.4.0","author":{"name":"American Councils"},"repository":{"type":"git","url":"https://github.com/AmericanCouncils/secure-ng-resource.git"},"main":"build/secure-ng-resource.min.js","dependencies":{"angular":"1.2.x"},"devDependencies":{"jasmine-node":"1.2.0","grunt-karma":"0.8.2","grunt-contrib-uglify":"0.4.0","grunt-contrib-jshint":"0.10.0","grunt-contrib-clean":"0.5.0","grunt-jsdoc":"0.5.4","karma-jasmine":"0.1.5","karma-phantomjs-launcher":"0.1.4"},"description":"[![Build Status](https://travis-ci.org/AmericanCouncils/secure-ng-resource.png?branch=master)](https://travis-ci.org/AmericanCouncils/secure-ng-resource)","bugs":{"url":"https://github.com/AmericanCouncils/secure-ng-resource/issues"},"_id":"secure-ng-resource@0.4.0","dist":{"shasum":"6c7b209924d5c9e08fefe18693e51acf8457c4c3","tarball":"https://registry.npmjs.org/secure-ng-resource/-/secure-ng-resource-0.4.0.tgz","integrity":"sha512-x651nq09K0fmXWctlqrM/Sc+GHO2syxlt0oVJ2JrW7wKZhk5o5WtlSjC0UWcDWqZGQRJM+Pa5wHf8uWpDPRtSA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDlY/3E7GRRWWrSSdzU1e1DB6WUi2Q4CfnPaattq1JjLwIhANGHiuaws/CVx11mGsd4H38fzl8YvLyRj5z8G9+4ScsM"}]},"_from":".","_npmVersion":"1.3.11","_npmUser":{"name":"davidmikesimon","email":"dsimon@americancouncils.org"},"maintainers":[{"name":"davidmikesimon","email":"dsimon@americancouncils.org"}]},"0.5.1":{"name":"secure-ng-resource","version":"0.5.1","author":{"name":"American Councils"},"repository":{"type":"git","url":"https://github.com/AmericanCouncils/secure-ng-resource.git"},"main":"build/secure-ng-resource.min.js","dependencies":{"angular":"1.2.x"},"devDependencies":{"jasmine-node":"1.2.0","grunt-karma":"0.8.2","grunt-contrib-uglify":"0.4.0","grunt-contrib-jshint":"0.10.0","grunt-contrib-clean":"0.5.0","grunt-jsdoc":"0.5.4","grunt-cli":"0.1.6","karma-jasmine":"0.1.5","karma-phantomjs-launcher":"0.1.4","bower":"1.3.8"},"description":"[![Build Status](https://travis-ci.org/AmericanCouncils/secure-ng-resource.png?branch=master)](https://travis-ci.org/AmericanCouncils/secure-ng-resource)","bugs":{"url":"https://github.com/AmericanCouncils/secure-ng-resource/issues"},"homepage":"https://github.com/AmericanCouncils/secure-ng-resource","_id":"secure-ng-resource@0.5.1","_shasum":"51211a45910887b336337cdb8cd703305ef3d5a0","_from":".","_npmVersion":"1.4.10","_npmUser":{"name":"davidmikesimon","email":"dsimon@americancouncils.org"},"maintainers":[{"name":"davidmikesimon","email":"dsimon@americancouncils.org"}],"dist":{"shasum":"51211a45910887b336337cdb8cd703305ef3d5a0","tarball":"https://registry.npmjs.org/secure-ng-resource/-/secure-ng-resource-0.5.1.tgz","integrity":"sha512-CzJ5wypsQTxW7oCYl7ymKwhY++Mjcii+I5rgtR0SwOTSkslh10pkCqg7vEgHM9Y+fHvVzig+ReaWtvqhwE0jXA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCbvHlur+GRyIyEIotFAfBfVT9tt48S2aJHaslSLogK+gIhAITnBbQ3+LDRD3GTURQxfjDpHZeqea5poT6MScxb+5ZQ"}]}}},"dist-tags":{"latest":"0.5.1"},"readmeFilename":"README.md","repository":{"type":"git","url":"https://github.com/AmericanCouncils/secure-ng-resource.git"},"author":{"name":"American Councils"},"bugs":{"url":"https://github.com/AmericanCouncils/secure-ng-resource/issues"},"homepage":"https://github.com/AmericanCouncils/secure-ng-resource"}