visa-passport
v0.1.0
Published
Simple, permission-backend agnostic, activity/role based authorization for Express based applications.
Downloads
11
Maintainers
Readme
Visa-passport
Visa-passport is a Express-compatible authorization provider.
Visa-passport purpose is to manage role based authorization but it does through resource/activity checks (see this), which enables not hardcode roles in code. It's database/backend agnostic, if a backend implementation plugin exists for your database it can manage authorization for you. Visa-passport assumes a particular database schema, but you can override its implementation to suit with your app, which maximizes flexiblity and allows application-level decisions to be made by the developer.
The API is simple: you provide a method to find the user in your app, and Visa-passport provides methods and middleware for manage authorization through your database/backend.
This module is not dependent but heavily inspired by Passport.js and works great with this module.
Install
npm install visa-passport
Usage
Get user
Because Visa-passport not handle authentication, it exposes visa.getUser(fn)
for identify the user in your app, you can pass the user to done(err, user)
from the request object or read it from your database.
visa.getUser(function(req, done) {
done(null, req.user);
});
Configure Backend
Visa-passport uses backend implementations for find the permissions in your app, for configure a backend, call visa.use(new MyFavoriteBackendImplementation)
.
visa.use(new visa.MemoryBackend());
Middleware
To use Visa-passport in an Express or
Connect-based application configure it
with the required visa.initialize()
middleware.
app.use(express.static(__dirname + '/public'));
app.use(cookieParser());
app.use(bodyParser());
app.use(session({ secret: 'SECRET' }));
app.use(passport.initialize());
app.use(passport.session());
app.use(visa.initialize())
Authorize Requests
Visa-passport provides an authorize()
function, which is used as route
middleware to authorize requests.
app.post('/forbidden', visa.authorize({ failureRedirect: '/unauthorized' }),
function(req, res) {
res.render('forbidden');
});
Backend Implementations
- MemoryBackend: Read a json file with your permissions and store them in memory
API
..WORK IN PROGRESS..
Examples
Future Work
- Mongodb backend implementation
- add more methods for manage authorization
- add session-cache support for authorization results
License
Copyright (c) 2014 BJR Matos <https://github.com/borismcr9/> Licensed under the MIT license.