{"_id":"u2f","_rev":"10-82ccd1fab4ecff10952c5ebc0d53d2a6","name":"u2f","description":"U2F 2-factor authentication library","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"u2f","version":"0.1.0","description":"U2F 2-factor authentication library","repository":{"type":"git","url":"https://github.com/ashtuchkin/node-u2f"},"keywords":["U2F","2-factor","authentication"],"author":{"name":"Alexander Shtuchkin","email":"ashtuchkin@gmail.com"},"license":"MIT","bugs":{"url":"https://github.com/ashtuchkin/node-u2f/issues"},"homepage":"https://github.com/ashtuchkin/node-u2f","dependencies":{"node-hid":"^0.3.1"},"_id":"u2f@0.1.0","scripts":{},"_shasum":"c8a42489e8df908a2e3825a6150255698b073f68","_from":".","_npmVersion":"1.4.28","_npmUser":{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"},"maintainers":[{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"}],"dist":{"shasum":"c8a42489e8df908a2e3825a6150255698b073f68","tarball":"https://registry.npmjs.org/u2f/-/u2f-0.1.0.tgz","integrity":"sha512-3SZ5T+Ol1aTNvzXXLQ6LR8/l8+HwlcxCnlTi3BpNOdEzyJ+BRmygSCKAENjMhv2IZzlu43QDGXqPttU1t7MaMw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDq/+fqrlkxQAUgAL6NZpQ122clF1DtOWx3/UhIliPvrQIhAM0TFKZEmT1vltB517t0H9SPjRRrF6meTKvD76Je34Bb"}]}},"0.1.1":{"name":"u2f","version":"0.1.1","description":"U2F 2-factor authentication library","repository":{"type":"git","url":"https://github.com/ashtuchkin/u2f"},"keywords":["U2F","2-factor","authentication"],"author":{"name":"Alexander Shtuchkin","email":"ashtuchkin@gmail.com"},"license":"MIT","bugs":{"url":"https://github.com/ashtuchkin/u2f/issues"},"homepage":"https://github.com/ashtuchkin/u2f","devDependencies":{"mocha":"2"},"gitHead":"2a9559b68b707a630d18bd878c2826d0fee60fad","_id":"u2f@0.1.1","scripts":{},"_shasum":"98e8e58c475ae1d4e13f585933907db1d4d79135","_from":".","_npmVersion":"2.1.6","_nodeVersion":"0.10.33","_npmUser":{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"},"maintainers":[{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"}],"dist":{"shasum":"98e8e58c475ae1d4e13f585933907db1d4d79135","tarball":"https://registry.npmjs.org/u2f/-/u2f-0.1.1.tgz","integrity":"sha512-Nyc6U8pAKJXcQ9CpBfoaIIIAL8cQdYCDsuqFb68joitVx2mHk3F7+t2g41jzN02WQFK/Ov+9a9xbJoGFSoEjSw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQChtN5q29LbT/kBWn4HfooCu/r+Cq5a93cwQFH2C4JsiAIhAO/pH4oLECPkl5uAgokdLi0nWkXLZ+yJKFaa3jAA8/5q"}]}},"0.1.2":{"name":"u2f","version":"0.1.2","description":"U2F 2-factor authentication library","repository":{"type":"git","url":"https://github.com/ashtuchkin/u2f"},"keywords":["U2F","2-factor","authentication"],"author":{"name":"Alexander Shtuchkin","email":"ashtuchkin@gmail.com"},"license":"MIT","bugs":{"url":"https://github.com/ashtuchkin/u2f/issues"},"homepage":"https://github.com/ashtuchkin/u2f","devDependencies":{"mocha":"2"},"gitHead":"5d56de5877d0c36b1b6a98ab38554fae63e8a8f0","_id":"u2f@0.1.2","scripts":{},"_shasum":"981b7bec7f910c1fa2956ac41fa940e10be6b1fb","_from":".","_npmVersion":"2.14.4","_nodeVersion":"4.1.1","_npmUser":{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"},"maintainers":[{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"}],"dist":{"shasum":"981b7bec7f910c1fa2956ac41fa940e10be6b1fb","tarball":"https://registry.npmjs.org/u2f/-/u2f-0.1.2.tgz","integrity":"sha512-jJS1Fu72BBwbq4ZoNg76Lorf8SLN/ZL5HPdVPVSRzxlSIHJ2641Z8t7Uio/F/5GvrvuOFU9PkysTunRnMZFtHg==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDcY04SWjuUQNIL2jrXvMAT6808UmehL8qXArrjzVaXbAIhAPpdqSp9BwXJGQ4vLT5DwWbR2EZ1eMBxHdruGreEwGZ0"}]}},"0.1.3":{"name":"u2f","version":"0.1.3","description":"U2F 2-factor authentication library","repository":{"type":"git","url":"git+https://github.com/ashtuchkin/u2f.git"},"keywords":["U2F","2-factor","authentication"],"author":{"name":"Alexander Shtuchkin","email":"ashtuchkin@gmail.com"},"license":"MIT","bugs":{"url":"https://github.com/ashtuchkin/u2f/issues"},"homepage":"https://github.com/ashtuchkin/u2f","devDependencies":{"mocha":"2"},"gitHead":"667959e143ffb761f3193fc588344515b063e9f8","_id":"u2f@0.1.3","_npmVersion":"5.4.2","_nodeVersion":"8.1.0","_npmUser":{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"},"dist":{"integrity":"sha512-/IaxeBqjo5o3D7plPkxdApbCpgGoI2bmTomS1kq5OjVflaE9UBJ0WfqoXqZryZKfFYBjQC7Tn1hA57WtRgh/Sg==","shasum":"a13afabe73fe8c67a4c2efe34dc866409e6d241b","tarball":"https://registry.npmjs.org/u2f/-/u2f-0.1.3.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFdp7MNbVeiN2Z7RDmN5WLjISzFqrRZy6YiMiHLCKZXZAiEArZz/06cxeqtpqQ/KleiqvZIYOaTXjxTEv8/iN3LS8Mc="}]},"maintainers":[{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/u2f-0.1.3.tgz_1507702423850_0.08497009216807783"}}},"readme":"# U2F authentication library\n\nThis is a simple library to register and check signatures provided by U2F clients/devices.\nIt's intended to be used in Relying Parties - websites that want to add U2F 2-factor authentication\nfor their users.\n\nTo use U2F, it is recommended to familiarize yourself with [FIDO Alliance Specifications](https://fidoalliance.org/download/),\nalthough basic usage is shown below.\n\n## U2F Overview/properties\n\n * U2F provides hardware-based 2-nd factor authentication system. Public/private key infrastructure is used\n   to ensure good security.\n * Provides proof of posession of hardware key, plus user presence flag.\n * Public/private key pairs are specific to website origin and 'application id'. Keys are useless if used from\n   other origins.\n * Needs to be stored on server for each user: Key handle and public key (both strings).\n * Cannot be used as main authentication system because server needs to provide\n   unique key handle to the user to get the signature.\n\n## Basic usage\n\n### User Registration Flow\n\n##### Server endpoints:\n\n```javascript\nconst u2f = require('u2f');\n\n// The app ID is a string used to uniquely identify your U2F app, for both registration requests and\n// authentication requests. It is usually the fully qualified URL of your website. The website MUST\n// be HTTPS, otherwise the registration will fail client-side.\nconst APP_ID = ...\n\nfunction registrationChallengeHandler(req, res) {\n  // 1. Check that the user is logged in.\n\n  // 2. Generate a registration request and save it in the session.\n  const registrationRequest = u2f.request(APP_ID);\n  req.session.registrationRequest = registrationRequest;\n\n  // 3. Send the registration request to the client, who will use the Javascript U2F API to sign\n  // the registration request, and send it back to the server for verification. The registration\n  // request is a JSON object containing properties used by the client to sign the request.\n  return res.send(registrationRequest);\n}\n\nfunction registrationVerificationHandler(req, res) {\n  // 4. Verify the registration response from the client against the registration request saved\n  // in the server-side session.\n  const result = u2f.checkRegistration(req.session.registrationRequest, req.body.registrationResponse);\n\n  if (result.successful) {\n    // Success!\n    // Save result.publicKey and result.keyHandle to the server-side datastore, associated with\n    // this user.\n    return res.sendStatus(200);\n  }\n\n  // result.errorMessage is defined with an English-language description of the error.\n  return res.send({result});\n}\n```\n\n##### Client logic:\n\nNote that the `window.u2f` object is defined in the official [Javascript U2F API](https://github.com/google/u2f-ref-code), for which a polyfill is [available as an npm module](https://www.npmjs.com/package/u2f-api-polyfill).\n\n```javascript\nconst registrationRequest = ...  // Retrieve this from hitting the registration challenge endpoint\n\nwindow.u2f.register(registrationRequest.appId, [registrationRequest], [], (registrationResponse) => {\n  // Send this registration response to the registration verification server endpoint\n});\n```\n\n### User Authentication Flow\n\n##### Server endpoints:\n\n```javascript\nconst u2f = require('u2f');\n\nfunction authenticationChallengeHandler(req, res) {\n  // 1. Check that the user is logged in using password authentication.\n\n  // 2. Fetch the user's key handle from the server-side datastore. This field should have been\n  // saved after the registration procedure.\n  const keyHandle = ...\n\n  // 3. Generate an authentication request and save it in the session. Use the same app ID that\n  // was used in registration!\n  const authRequest = u2f.request(APP_ID, keyHandle);\n  req.session.authRequest = authRequest;\n\n  // 4. Send the authentication request to the client, who will use the Javascript U2F API to sign\n  // the authentication request, and send it back to the server for verification.\n  return res.send(authRequest);\n}\n\nfunction authenticationVerificationHandler(req, res) {\n  // 5. Fetch the user's public key from the server-side datastore. This field should have been\n  // saved after the registration procedure.\n  const publicKey = ...\n\n  // 6. Verify the authentication response from the client against the authentication request saved\n  // in the server-side session.\n  const result = u2f.checkSignature(req.session.authRequest, req.body.authResponse, publicKey);\n\n  if (result.successful) {\n    // Success!\n    // User is authenticated.\n    return res.sendStatus(200);\n  }\n\n  // result.errorMessage is defined with an English-language description of the error.\n  return res.send({result});\n}\n```\n\n##### Client logic:\n\n```javascript\nconst authRequest = ...;  // Retrieve this from hitting the authentication challenge endpoint\n\nwindow.u2f.sign(authRequest.appId, challenge, [authRequest], (authResponse) => {\n  // Send this authentication response to the authentication verification server endpoint\n});\n```\n\n## Useful links\n\nhttp://demo.yubico.com/u2f  \nhttps://github.com/Yubico/python-u2flib-server  \n\n\n\n## TODO\n\n * Provide instructions for client-side. How to get the 'u2f' namespace, what browsers are supported.\n * Change API to enable multiple keyhandle/publickey pairs for a single user.\n * Unpack registration certificate and check its own signature and time constraints.\n\n\n# License\n\nMIT\n","maintainers":[{"name":"ashtuchkin","email":"ashtuchkin@gmail.com"}],"time":{"modified":"2022-06-28T02:29:34.339Z","created":"2014-10-22T06:17:19.933Z","0.1.0":"2014-10-22T06:17:19.933Z","0.1.1":"2014-11-04T12:22:57.952Z","0.1.2":"2015-12-09T03:37:39.957Z","0.1.3":"2017-10-11T06:13:43.955Z"},"homepage":"https://github.com/ashtuchkin/u2f","keywords":["U2F","2-factor","authentication"],"repository":{"type":"git","url":"git+https://github.com/ashtuchkin/u2f.git"},"author":{"name":"Alexander Shtuchkin","email":"ashtuchkin@gmail.com"},"bugs":{"url":"https://github.com/ashtuchkin/u2f/issues"},"license":"MIT","readmeFilename":"README.md","users":{"fillup":true}}