# azure-token-verify-http

> This authorization module is intended to check Azure Graph token validity by performing a token validation paired with a username.

Latest version **1.1.1** (published 2019-02-05) · MIT license · 0 weekly downloads

## Install

```sh
npm install azure-token-verify-http
pnpm add azure-token-verify-http
yarn add azure-token-verify-http
bun add azure-token-verify-http
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.1.1 |
| Published | 2019-02-05 |
| First published | 2019-01-24 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 2 |
| Unpacked size | 5.3 KB |
| Known vulnerabilities | 0 (+1 in 1 direct dependencies) |
| Install scripts | no |
| Author | Tommaso Bastianello |
| Maintainers | tommaso.bastianello |
| Keywords | azure, auth, graph, token |

## Links

- npm: https://www.npmjs.com/package/azure-token-verify-http
- Repository: https://gitlab.com/tom.bastianello/azure-token-verify-http
- Homepage: https://gitlab.com/tom.bastianello/azure-token-verify-http#README
- Issues: https://gitlab.com/tom.bastianello/azure-token-verify-http/issues
- npm.io page: https://npm.io/package/azure-token-verify-http

## Dependencies (2)

- [cookie](https://npm.io/package/cookie.md) >=0.3.1
- [request](https://npm.io/package/request.md) >=2.88.0

## Alternatives

- [@clerk/clerk-expo](https://npm.io/package/@clerk/clerk-expo.md) — 133.6K weekly downloads
- [@pothos/plugin-authz](https://npm.io/package/@pothos/plugin-authz.md) — 12.4K weekly downloads
- [@bounded-sh/client](https://npm.io/package/@bounded-sh/client.md) — 3.2K weekly downloads
- [@luigi-project/plugin-auth-oauth2](https://npm.io/package/@luigi-project/plugin-auth-oauth2.md) — 2.3K weekly downloads
- [@nocobase/plugin-verification](https://npm.io/package/@nocobase/plugin-verification.md) — 2.0K weekly downloads

## Recent versions

- 1.1.1 (latest) — 2019-02-05
- 1.1.0 — 2019-01-29
- 1.0.7 — 2019-01-28
- 1.0.6 — 2019-01-28
- 1.0.5 — 2019-01-28
- 1.0.4 — 2019-01-24
- 1.0.3 — 2019-01-24
- 1.0.2 — 2019-01-24
- 1.0.1 — 2019-01-24
- 1.0.0 — 2019-01-24

## README

## Description
This module is intended as a back-end function for an HTTP server written in node.js.
It provides a way of verifying that a username and token pair are valid against Azure AD.

## Requirements
This module requires that the http request that was performend contains 2 cookies with data pertinent to the authorization process, these are listed below:
- '**azure_username**':	The username of the account to be verified.
- '**azure_token**':		The bearer token associated with the account to be verified; it is required that this token matches the username and cannot be associated to a different account.

## Inputs
The following inputs are required when calling the ```authorize()``` function in the module, these are as follow:
- '**origin_request**':	    The remote request object.
- '**origin_response**':    The remote response object (this is passed in the output to be used with the callback function).
- '**callback**': 		    The callback function that will be executed when the autorization porcess is completed.
- '**domain**':             Azure tenant email domain for verification, for example ```contoso.com```.

## Outputs
If both requirements are satisfied, the expected response will contain the following data:
 - '**request**':    	The original HTTP request object.
 - '**response**':   	The response object generated in response to the original request, used to perform response actions to the HTTP client.
 - '**callback**':   	A callback function that will be executed when the autorization process is complete.
 - '**domain**':        Azure tenant email domain that has been verified, for example ```contoso.com```.
 - '**username**':   	The username extracted from the 'azure_username' cookie.
 - '**token**':      	The token extracted from the 'azure_token' cookie.
 - '**authorized**': 	A booean flag that signifies if the account has passed the authrization process.
 
## Dependencies
  - '**cookie**':		'>=0.3.1',
  - '**request**':	    '>=2.88.0'
 
## Examples
```
// Importing the module.
const auth = require("azure-token-verify-http");

// Call the function with a callback (in this case a http response is generated and auth status is sent to the client).
auth.authorize(request, response, "contoso.com", function(event){
    event.response.write(JSON.stringify({"authorized": event.authorized, "username": event.username}));
    event.response.end();
});
```

## Links
- Node.js package: [here](https://www.npmjs.com/package/azure-token-verify-http)
- GitLab Repo: [here](https://gitlab.com/tom.bastianello/azure-token-verify-http)

---
_Source: https://npm.io/package/azure-token-verify-http · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
