npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2024 – Pkg Stats / Ryan Hefner

@microservice/auth-token

v2.0.0

Published

Microservice authentication tokens

Downloads

5

Readme

auth-token

Library for creating and encoding/decoding JWT-base auth tokens.

Install

$ npm install --save @microservice/auth-token

Usage

As a factory that uses a builder style pattern to configure things:

var Token = require('@microservice/auth-token').alg('HS512').secret('foo');
var token = Token.create();

This returns a plain old object that you attach the JWT claims to:

token.foo = 'blah';

console.log(token.foo); // 'blah'
console.log(token.alg); // 'HS512'
console.log(JSON.stringify(token)); // {"foo":blah"}
console.log(token.toString()); // the token as a signed string
console.log(token.toAuthorizationHeader()) // "JWT " + toString()
console.log(token.toXsrfToken()); // etc.

One advantage to this is if your tokens fall in to logs somewhere, the secret is nowhere to be seen.

You can specify claims as part of create:

token = Token.create({
	another: 'claim'
});

console.log(token.another); // 'claim'

... and decode an existing token:

// this works because token is just an object anyway
token = Token.create(token);

// this decodes the token, or returns null if that failed
token = Token.create(token.toString());

You can specify the secret, and algorithm during create, too:

var Factory = Token.alg('HS512').secret('secret');

// use the preconfigured secret and algorithm
one = Factory.create(incoming);

// use a different secret, but the same algorithm
two = Factory.create('other_secret', other_token);

// use a different algorithm and secret
three = Factory.create('HS256', 'other_secret', other_token);

You can also decode a token, which works like create:

var A = Token.secret('secret');
var B = Token.secret('different_secret');

// create a token using 'secret'
var a = A.create({ foo: 'bar' });

// encode the token
var encoded = a.toString();

// decode the token using 'secret' and copy the claims in to a new token
// that uses 'different_secret' as configured in the factory
var b = B.decode('secret', encoded);

Properties

You can configure the token factory with property aliases to give more meaningful names to things that might be terse in the token itself:

Token = Token.secret('foo').properties({ 'tenantId': 'aud' });
token = Factory.create();

token.tenantId = 'blah';

console.log(token.tenantId); // 'blah'
console.log(token.aud); // 'blah'
console.log(JSON.stringify(token)); // {"aud":"blah"}