npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2024 – Pkg Stats / Ryan Hefner

protobuf-web-token

v1.0.3

Published

Collection of libraries for different languages to implement signing/verification/decoding of tokens. The approach is similar to the one used in [JWT](https://jwt.io/introduction) (Json Web Token). The rest of this README assumes that you are familiar wha

Downloads

16

Readme

Protobuf Web Token (PWT)

Collection of libraries for different languages to implement signing/verification/decoding of tokens. The approach is similar to the one used in JWT (Json Web Token). The rest of this README assumes that you are familiar what JWTs are used for.

What is suboptimal with JWTs

The JSON format is rather inefficient to transfer data with in comparison to a compact binary encoding such as Protocol Buffers. It is in most cases both larger in size and takes longer to encode and decode. However, the advantages of JSON include its human-readability and its typeless nature - the client does not need to know all keys/all value types the server sends in a response. But in a scenario where you have both authorization server and application in your hands this seems like a disadvantage instead: There is a possibility for errors since there is an implicit dependency that will not be caught at compile time.

Protobuf to the rescue

So assuming we have both authorization server and application in our control we can do "better" (there are still coupling tradeoffs here of course).

We introduce a .proto file which contains the data we wish to put in the token. Examples:

  • The users id
  • The users name
  • The users email
  • A list of roles or permissions
  • ...

The token will also include standardized metadata which right now is just one field:

  • valid_until, a unix timestamp of the time where the token should expire

We generate the bindings for the languages using libraries or protoc plugins. For the currently supported languages these are:

Then the authorization server can use the sign method to sign an object which precisely matches the shape you defined in your .proto file and the client or other servers can use verify or decode to read the contents.

Supported Encryption Algorithms

Right now we only support Ed25519. Therefore, the token does not need to include information which verification algorithm needs to be used, which also helps to reduce the size a bit more.