{"_id":"socketio-auth","_rev":"20-a8339e34bdf46b03c6861cefb76db077","name":"socketio-auth","description":"Authentication for socket.io","dist-tags":{"latest":"0.1.1"},"versions":{"0.0.1":{"name":"socketio-auth","version":"0.0.1","description":"Authentication for socket.io","main":"index.js","directories":{"test":"test"},"scripts":{"test":"node_modules/mocha/bin/mocha"},"repository":{"type":"git","url":"https://github.com/invisiblejs/socketio-auth"},"keywords":["socket","socket.io","authentication","auth","invisible.js"],"author":{"name":"Facundo Olano and Martín Paulucci"},"license":"ISC","bugs":{"url":"https://github.com/invisiblejs/socketio-auth/issues"},"homepage":"https://github.com/invisiblejs/socketio-auth","dependencies":{"underscore":"^1.7.0","winston":"^0.8.1"},"devDependencies":{"mocha":"^1.21.5"},"_id":"socketio-auth@0.0.1","_shasum":"d89b1a21303d67a966fa68652e308523c6c0659e","_from":".","_npmVersion":"1.4.9","_npmUser":{"name":"facundoolano","email":"facundo.olano@gmail.com"},"maintainers":[{"name":"facundoolano","email":"facundo.olano@gmail.com"}],"dist":{"shasum":"d89b1a21303d67a966fa68652e308523c6c0659e","tarball":"https://registry.npmjs.org/socketio-auth/-/socketio-auth-0.0.1.tgz","integrity":"sha512-dhF+vgE2GiaTRY2J0WKRAkFn1+aab32fwUIJrtd5wiGaiIvC/slXepVeqhIIIXvD145gtg1yhTC9lwUHTTAFbA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCo6chc+iNc6qm4QZRGC+bXWrYhnoL1jSuzESJE+0ZmQAIgIEf+0KTAhFKBjy2OF2FqwnhrcAKDEbDjgz0bq9dBGKk="}]}},"0.0.2":{"name":"socketio-auth","version":"0.0.2","description":"Authentication for socket.io","main":"index.js","directories":{"test":"test"},"scripts":{"test":"node_modules/mocha/bin/mocha"},"repository":{"type":"git","url":"https://github.com/invisiblejs/socketio-auth"},"keywords":["socket","socket.io","authentication","auth","invisible.js"],"author":{"name":"Facundo Olano and Martín Paulucci"},"license":"ISC","bugs":{"url":"https://github.com/invisiblejs/socketio-auth/issues"},"homepage":"https://github.com/invisiblejs/socketio-auth","dependencies":{"debug":"^2.1.3","underscore":"^1.7.0"},"devDependencies":{"mocha":"^1.21.5"},"gitHead":"08760f11bced4804ea8fdc8616d737ed0740f2dc","_id":"socketio-auth@0.0.2","_shasum":"afbdbe54e2d08971a9ca409fc54467aa5a5bd4fb","_from":".","_npmVersion":"1.4.28","_npmUser":{"name":"facundoolano","email":"facundo.olano@gmail.com"},"maintainers":[{"name":"facundoolano","email":"facundo.olano@gmail.com"}],"dist":{"shasum":"afbdbe54e2d08971a9ca409fc54467aa5a5bd4fb","tarball":"https://registry.npmjs.org/socketio-auth/-/socketio-auth-0.0.2.tgz","integrity":"sha512-rpJ9fKHA3EDGo8ixJOVQMoP42RyiS8ajVXhuw1ZCtSF6ePIWkN3QRr4eXYVaGk2aUY8RqS8lTbnw7MS+IkGbYw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDpR9WkcltWmHwT6rEpN4VQ7W2POUywZMH7B+B2QSfX1gIgIZ2mnPh37p/kH1YdXTx8u/HdtrBIePCaY+MTOr6+DA4="}]}},"0.0.3":{"name":"socketio-auth","version":"0.0.3","description":"Authentication for socket.io","main":"index.js","directories":{"test":"test"},"scripts":{"jscs":"jscs lib/ test/","jshint":"jshint lib/ test/","lint":"npm run jshint && npm run jscs","pretest":"npm run lint","test":"mocha"},"repository":{"type":"git","url":"https://github.com/invisiblejs/socketio-auth"},"keywords":["socket","socket.io","authentication","auth","invisible.js"],"author":{"name":"Facundo Olano and Martín Paulucci"},"license":"ISC","bugs":{"url":"https://github.com/invisiblejs/socketio-auth/issues"},"homepage":"https://github.com/invisiblejs/socketio-auth","dependencies":{"debug":"^2.1.3","lodash":"^3.8.0"},"devDependencies":{"jscs":"~1.8.0","jshint":"~2.5.10","mocha":"^1.21.5"},"gitHead":"0bc0d5d7c0489df8d2fc0c06fbefd1a34f4b6b75","_id":"socketio-auth@0.0.3","_shasum":"2f0f1d5c7c75f26caf388f6d370ae3eedf377138","_from":".","_npmVersion":"1.4.28","_npmUser":{"name":"facundoolano","email":"facundo.olano@gmail.com"},"maintainers":[{"name":"facundoolano","email":"facundo.olano@gmail.com"}],"dist":{"shasum":"2f0f1d5c7c75f26caf388f6d370ae3eedf377138","tarball":"https://registry.npmjs.org/socketio-auth/-/socketio-auth-0.0.3.tgz","integrity":"sha512-WV8HDCJJeGtPvnWiOlK8EdRNx+HGEpqT+jKs93QgKwUkHC4yfsr41eoccEP4NQrBeSd0GpP9p9sqbCJ8q8YYHw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEpWw6R3sIOjmCbt1YHXsQkJJ7Dxhag/axJVJ53jqbhCAiBvlylGXZ5QfytSafvvDIDvn/0Yjgi6PAJwNYUGjPt+4w=="}]}},"0.0.4":{"name":"socketio-auth","version":"0.0.4","description":"Authentication for socket.io","main":"index.js","directories":{"test":"test"},"scripts":{"jscs":"jscs lib/ test/","jshint":"jshint lib/ test/","lint":"npm run jshint && npm run jscs","pretest":"npm run lint","test":"mocha"},"repository":{"type":"git","url":"https://github.com/facundoolano/socketio-auth"},"keywords":["socket","socket.io","authentication","auth","invisible.js"],"author":{"name":"Facundo Olano and Martín Paulucci"},"license":"ISC","bugs":{"url":"https://github.com/facundoolano/socketio-auth/issues"},"homepage":"https://github.com/facundoolano/socketio-auth","dependencies":{"debug":"^2.1.3","lodash":"^3.8.0"},"devDependencies":{"jscs":"~1.8.0","jshint":"~2.5.10","mocha":"^1.21.5"},"gitHead":"26ab33d272a89aebe231a4b2ac298fdf71421496","_id":"socketio-auth@0.0.4","_shasum":"144a5ba57bfcba9cd0ea34f4bb265f06c92f02b5","_from":".","_npmVersion":"1.4.28","_npmUser":{"name":"facundoolano","email":"facundo.olano@gmail.com"},"maintainers":[{"name":"facundoolano","email":"facundo.olano@gmail.com"}],"dist":{"shasum":"144a5ba57bfcba9cd0ea34f4bb265f06c92f02b5","tarball":"https://registry.npmjs.org/socketio-auth/-/socketio-auth-0.0.4.tgz","integrity":"sha512-4IS2BUtdT189aR9O3HZHSxWzV9TY8Y+ol7nLrb11dAY3Xv1rQ3/JuxdvKZMcWY2EIv5N81npsqR0kvO1dl0mjw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHNj284GBPXJ356hSp7PWDw7nZv6/iUYQyfJCEJHSQbkAiEAyBwb/YCX28+HzE/ecmNwX5VIJ2AfbOumHAee+sXEgmQ="}]}},"0.0.5":{"name":"socketio-auth","version":"0.0.5","description":"Authentication for socket.io","main":"index.js","directories":{"test":"test"},"scripts":{"jscs":"jscs lib/ test/","jshint":"jshint lib/ test/","lint":"npm run jshint && npm run jscs","pretest":"npm run lint","test":"mocha"},"repository":{"type":"git","url":"https://github.com/facundoolano/socketio-auth"},"keywords":["socket","socket.io","authentication","auth","invisible.js"],"author":{"name":"Facundo Olano and Martín Paulucci"},"license":"ISC","bugs":{"url":"https://github.com/facundoolano/socketio-auth/issues"},"homepage":"https://github.com/facundoolano/socketio-auth","dependencies":{"debug":"^2.1.3","lodash":"^3.8.0"},"devDependencies":{"jscs":"~1.8.0","jshint":"~2.5.10","mocha":"^1.21.5"},"gitHead":"3ad8ec2e852a74bdd13c9298744bd587da148850","_id":"socketio-auth@0.0.5","_shasum":"0529c858cbc54c37acf0198d900e441553e832aa","_from":".","_npmVersion":"1.4.28","_npmUser":{"name":"facundoolano","email":"facundo.olano@gmail.com"},"maintainers":[{"name":"facundoolano","email":"facundo.olano@gmail.com"}],"dist":{"shasum":"0529c858cbc54c37acf0198d900e441553e832aa","tarball":"https://registry.npmjs.org/socketio-auth/-/socketio-auth-0.0.5.tgz","integrity":"sha512-JKoMyPhADNbNy4DxGVfPAewPvsIb5bpDE930m9DpEy3wml+ToNoh1V/jK0QIl788KnKJV2Dfu+1EHqfmDGVh0A==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDSeX8t5MaWwUpfta+/NmTqR0r05dZTBmNs6y3t3oayngIgCyyRd/mlFLZyxHtAQI3DZvIr9rxqIrBhIeKDzinBMpU="}]}},"0.1.0":{"name":"socketio-auth","version":"0.1.0","description":"Authentication for socket.io","main":"index.js","directories":{"test":"test"},"scripts":{"jscs":"jscs lib/ test/","jshint":"jshint lib/ test/","lint":"npm run jshint && npm run jscs","pretest":"npm run lint","test":"mocha"},"repository":{"type":"git","url":"git+https://github.com/facundoolano/socketio-auth.git"},"keywords":["socket","socket.io","authentication","auth","invisible.js"],"author":{"name":"Facundo Olano and Martín Paulucci"},"license":"ISC","bugs":{"url":"https://github.com/facundoolano/socketio-auth/issues"},"homepage":"https://github.com/facundoolano/socketio-auth","dependencies":{"debug":"^2.1.3","lodash":"^3.8.0"},"devDependencies":{"jscs":"~1.8.0","jshint":"~2.5.10","mocha":"^1.21.5"},"gitHead":"7ea8eeb09b4dab02f31a0fb8745f508f36c63d85","_id":"socketio-auth@0.1.0","_shasum":"467486874057cd4a3d9ac5ca6ebe9c3310dfba33","_from":".","_npmVersion":"3.8.6","_nodeVersion":"5.9.1","_npmUser":{"name":"facundoolano","email":"facundo.olano@gmail.com"},"dist":{"shasum":"467486874057cd4a3d9ac5ca6ebe9c3310dfba33","tarball":"https://registry.npmjs.org/socketio-auth/-/socketio-auth-0.1.0.tgz","integrity":"sha512-9pJG0eShVhFVzKr3eU7OMwEN9ZOB/xpjwS7WjeZDLjyo99oeuZ0STU8uiGZ9t+my6BqEa6G9CN72/pFUMTkn7Q==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD39MDrVMH0v15ORQAReoUQAnwvrTZmsFTd/uFGofI7kQIhAI4Y98NMYeadl9ybLCV+HGmDojBgsLpJIcCSYdd+GHdx"}]},"maintainers":[{"name":"facundoolano","email":"facundo.olano@gmail.com"}],"_npmOperationalInternal":{"host":"packages-18-east.internal.npmjs.com","tmp":"tmp/socketio-auth-0.1.0.tgz_1477003721552_0.7771660478319973"}},"0.1.1":{"name":"socketio-auth","version":"0.1.1","description":"Authentication for socket.io","main":"index.js","directories":{"test":"test"},"scripts":{"jscs":"jscs lib/ test/","jshint":"jshint lib/ test/","lint":"npm run jshint && npm run jscs","pretest":"npm run lint","test":"mocha"},"repository":{"type":"git","url":"git+https://github.com/facundoolano/socketio-auth.git"},"keywords":["socket","socket.io","authentication","auth","invisible.js"],"author":{"name":"Facundo Olano and Martín Paulucci"},"license":"ISC","bugs":{"url":"https://github.com/facundoolano/socketio-auth/issues"},"homepage":"https://github.com/facundoolano/socketio-auth","dependencies":{"debug":"^2.1.3","lodash":"^4.17.5"},"devDependencies":{"jscs":"~1.8.0","jshint":"~2.5.10","mocha":"^1.21.5"},"gitHead":"06382514ca2589f940cd86010e4ebedafb3aa502","_id":"socketio-auth@0.1.1","_npmVersion":"5.6.0","_nodeVersion":"9.9.0","_npmUser":{"name":"facundoolano","email":"facundo.olano@gmail.com"},"dist":{"integrity":"sha512-TDM/yiA5tnDiJqn8fO5zHrvTaKmN4EK4Dci9RaJLO11LEEbC1/E7z352OFrIWg8d/rn+Nk666ks9RhjlkGILlA==","shasum":"03f1fdd9d9b5e10f0a0ea9502abadbc580015d71","tarball":"https://registry.npmjs.org/socketio-auth/-/socketio-auth-0.1.1.tgz","fileCount":9,"unpackedSize":16075,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJa+XzFCRA9TVsSAnZWagAA/ysP/3qI80h2NidZE8VeZqwE\nmVmQjgb/zOAxIL83BgDtWghnmPUrf/6OkA2aaTXjYOilI9VmJ7ipFsF0z0Gq\nHsnKjVXUsuopDWzrvxnc8X+ZZOb3lPfQIl6I5wC7BG0K2+St30Rs8Vnm416q\nkRAUCfNxH06wAQ1RQZl9BlNdX3UJ76BZ3y6ChCoKK5fqeMtng3lRJDEmz1D/\nOJWZv5whUH1eAWfZ11l1KXYF7PGSY2Z6PNZsjmptgV83dPpaCVz2ZG/+E5gS\nNygvRMyB8b493Ne3S/Z09RyxAM+HLmKAT6zv0xV2AcaKDbDZYwpwj7hvgkyI\nL/GOtbfw1x87hv4Znjh0xHyJhQ9HL3AbbsNJmU8HQopiL/U9wPTJU+WKN7Ct\nMsTeWjOqAjRiFMnyI7xXO8hv7dg7OPT1vwfirO4Xn57JEX/KNe+X9EAx/eE7\nuGkUNxxtDCXu1t0MIwpmsGBNWYbl9QYVgTp4g9+TM0uGfrxH9MlrtyyWjZU8\nZTkpEXHdJL5goxe8p2Bpv99XMomA7IK9GFAwPe1oKWNJ+PiCQd7MxJ7ogXmQ\nn05P7PYvdhwuqWQtikhtjuU3gvAOCcTQq2rZ2U3rrm3h89RXX34Z3eTacmF0\nisiRyvVriBn/wmsyWlfBUCK7fDv/OtAlcYO1YHDv8T5vejCQDCqe5DyOERc3\niphM\r\n=SYhn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBjrwiyCeJuE+4+V82jOiiRrQJuQnBckeht1Z2ISN9O/AiBGBrqy2e0wFV2or3PRM7CrP18veyumiBCm00zppWf0gw=="}]},"maintainers":[{"name":"facundoolano","email":"facundo.olano@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/socketio-auth_0.1.1_1526299844533_0.8162868508262435"},"_hasShrinkwrap":false}},"readme":"# socketio-auth [![Build Status](https://secure.travis-ci.org/facundoolano/socketio-auth.png)](http://travis-ci.org/facundoolano/socketio-auth)\n\nThis module provides hooks to implement authentication in [socket.io](https://github.com/Automattic/socket.io) without using querystrings to send credentials, which is not a good security practice.\n\nClient:\n```javascript\nvar socket = io.connect('http://localhost');\nsocket.on('connect', function(){\n  socket.emit('authentication', {username: \"John\", password: \"secret\"});\n  socket.on('authenticated', function() {\n    // use the socket as usual\n  });\n});\n```\n\nServer:\n```javascript\nvar io = require('socket.io').listen(app);\n\nrequire('socketio-auth')(io, {\n  authenticate: function (socket, data, callback) {\n    //get credentials sent by the client\n    var username = data.username;\n    var password = data.password;\n\n    db.findUser('User', {username:username}, function(err, user) {\n\n      //inform the callback of auth success/failure\n      if (err || !user) return callback(new Error(\"User not found\"));\n      return callback(null, user.password == password);\n    });\n  }\n});\n```\n\nThe client should send an `authentication` event right after connecting, including whatever credentials are needed by the server to identify the user (i.e. user/password, auth token, etc.). The `authenticate` function receives those same credentials in 'data', and the actual 'socket' in case header information like the origin domain is important, and uses them to authenticate.\n\n## Configuration\n\nTo setup authentication for the socket.io connections, just pass the server socket to socketio-auth with a configuration object:\n\n```javascript\nvar io = require('socket.io').listen(app);\n\nrequire('socketio-auth')(io, {\n  authenticate: authenticate,\n  postAuthenticate: postAuthenticate,\n  disconnect: disconnect,\n  timeout: 1000\n});\n```\n\nThe supported parameters are:\n\n* `authenticate`: The only required parameter. It's a function that takes the data sent by the client and calls a callback indicating if authentication was successfull:\n\n```javascript\nfunction authenticate(socket, data, callback) {\n  var username = data.username;\n  var password = data.password;\n\n  db.findUser('User', {username:username}, function(err, user) {\n    if (err || !user) return callback(new Error(\"User not found\"));\n    return callback(null, user.password == password);\n  });\n}\n```\n* `postAuthenticate`: a function to be called after the client is authenticated. It's useful to keep track of the user associated with a client socket:\n\n```javascript\nfunction postAuthenticate(socket, data) {\n  var username = data.username;\n\n  db.findUser('User', {username:username}, function(err, user) {\n    socket.client.user = user;\n  });\n}\n```\n* `disconnect`: a function to be called after the client is disconnected.\n\n```javascript\nfunction disconnect(socket) {\n  console.log(socket.id + ' disconnected');\n}\n```\n\n* `timeout`: The amount of millisenconds to wait for a client to authenticate before disconnecting it. Defaults to 1000. The value 'none' disables the timeout feature.\n\n## Auth error messages\n\nWhen client authentication fails, the server will emit an `unauthorized` event with the failure reason:\n\n```javascript\nsocket.emit('authentication', {username: \"John\", password: \"secret\"});\nsocket.on('unauthorized', function(err){\n  console.log(\"There was an error with the authentication:\", err.message);\n});\n```\n\nThe value of `err.message` depends on the outcome of the `authenticate` function used in the server: if the callback receives an error its message is used, if the success parameter is false the message is `'Authentication failure'`\n\n```javascript\nfunction authenticate(socket, data, callback) {\n  db.findUser('User', {username:data.username}, function(err, user) {\n    if (err || !user) {\n      //err.message will be \"User not found\"\n      return callback(new Error(\"User not found\"));\n    }\n\n    //if wrong password err.message will be \"Authentication failure\"\n    return callback(null, user.password == data.password);\n  });\n}\n```\n\nAfter receiving the `unauthorized` event, the client is disconnected.\n\n## Implementation details\n\n**socketio-auth** implements two-step authentication: upon connection, the server marks the clients as unauthenticated and listens to an `authentication` event. If a client provides wrong credentials or doesn't authenticate after a timeout period it gets disconnected. While the server waits for a connected client to authenticate, it won't emit any broadcast/namespace events to it. By using this approach the sensitive authentication data, such as user credentials or tokens, travel in the body of a secure request, rather than a querystring that can be logged or cached.\n\nNote that during the window while the server waits for authentication, direct messages emitted to the socket (i.e. `socket.emit(msg)`) *will* be received by the client. To avoid those types of messages reaching unauthorized clients, the emission code should either be defined after the `authenticated` event is triggered by the server or the `socket.auth` flag should be checked to make sure the socket is authenticated.\n\nSee [this blog post](https://facundoolano.wordpress.com/2014/10/11/better-authentication-for-socket-io-no-query-strings/) for more details on this authentication method.\n","maintainers":[{"name":"facundoolano","email":"facundo.olano@gmail.com"}],"time":{"modified":"2022-06-26T21:58:06.353Z","created":"2014-10-16T23:54:36.085Z","0.0.1":"2014-10-16T23:54:36.085Z","0.0.2":"2015-05-09T16:12:12.091Z","0.0.3":"2015-06-06T03:51:33.572Z","0.0.4":"2015-08-24T12:48:29.986Z","0.0.5":"2015-11-04T16:36:24.790Z","0.1.0":"2016-10-20T22:48:43.643Z","0.1.1":"2018-05-14T12:10:44.678Z"},"homepage":"https://github.com/facundoolano/socketio-auth","keywords":["socket","socket.io","authentication","auth","invisible.js"],"repository":{"type":"git","url":"git+https://github.com/facundoolano/socketio-auth.git"},"author":{"name":"Facundo Olano and Martín Paulucci"},"bugs":{"url":"https://github.com/facundoolano/socketio-auth/issues"},"license":"ISC","readmeFilename":"README.md","users":{"temasm":true,"goliatone":true,"dpeukert":true,"freeface":true,"hyteer":true,"lukaserat":true,"panlw":true,"papasavva":true,"atton16":true}}