# baucis-decorator-auth

> Allows you to specify authentication parameters for properties within any `baucis` resource's `mongoose` schema and adds authentication routes.

Latest version **1.0.4** (published 2015-06-25) · MIT license · 0 weekly downloads

## Install

```sh
npm install baucis-decorator-auth
pnpm add baucis-decorator-auth
yarn add baucis-decorator-auth
bun add baucis-decorator-auth
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.4 |
| Published | 2015-06-25 |
| First published | 2015-06-03 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 8 |
| Known vulnerabilities | 0 (+12 in 3 direct dependencies) |
| Install scripts | no |
| Author | timbur |
| Maintainers | timbur |
| Keywords | baucis, decorator, authentication, resource |

## Links

- npm: https://www.npmjs.com/package/baucis-decorator-auth
- Repository: https://github.com/loggur/baucis-decorator-auth
- Homepage: https://github.com/loggur/baucis-decorator-auth#readme
- Issues: https://github.com/loggur/baucis-decorator-auth/issues
- npm.io page: https://npm.io/package/baucis-decorator-auth

## Dependencies (8)

- [baucis](https://npm.io/package/baucis.md) ^1.3.1
- [bcrypt](https://npm.io/package/bcrypt.md) ^0.8.3
- [express](https://npm.io/package/express.md) ^4.12.4
- [mongoose](https://npm.io/package/mongoose.md) >=4.0.4
- [nodemailer](https://npm.io/package/nodemailer.md) ^1.3.4
- [deep-extend](https://npm.io/package/deep-extend.md) ^0.4.0
- [baucis-decorators](https://npm.io/package/baucis-decorators.md) ^1.0.0
- [baucis-decorator-env](https://npm.io/package/baucis-decorator-env.md) ^1.0.0

## Alternatives

- [@clerk/clerk-expo](https://npm.io/package/@clerk/clerk-expo.md) — 133.6K weekly downloads
- [@pothos/plugin-authz](https://npm.io/package/@pothos/plugin-authz.md) — 12.4K weekly downloads
- [@bounded-sh/client](https://npm.io/package/@bounded-sh/client.md) — 3.2K weekly downloads
- [@oxyhq/services](https://npm.io/package/@oxyhq/services.md) — 2.3K weekly downloads
- [@luigi-project/plugin-auth-oauth2](https://npm.io/package/@luigi-project/plugin-auth-oauth2.md) — 2.3K weekly downloads

## Recent versions

- 1.0.4 (latest) — 2015-06-25
- 1.0.2 — 2015-06-15
- 1.0.1 — 2015-06-05
- 1.0.0 — 2015-06-03

## README

# baucis-decorator-auth
Allows you to specify authentication parameters for properties within any `baucis` resource's `mongoose` schema and adds authentication routes.

## Install
```
npm install baucis-decorators baucis-decorator-auth --save
```

## Usage
You'll need 5 properties for this.  The main one specifies who is currently authenticated to the resource and should contain an `auth` field, which contains references to the other 4 properties by the keys `password`, `enabler`, `designator`, and `resetter`, as well as a `roles` key that should optionally contain different sets of `Boolean` values for the access control.  It is probably easiest to just check out the example below.

Four endpoints are added, `login`, `logout`, `reset-password`, and `set-password`.  The password reset functionality is a WIP as it needs to allow for custom emails.  Also keep in mind that authentication and access control can work for any resource, not just users.

Following the example below, if some `User` has `publicViewing` set to `false` and POSTs the proper `id` (or `name`) and `viewingPassword` to `/api/users/login`, said `User` will be able to view the resource.  Alternatively, the `User` will be able to view the resource if they are in the `viewers` list.

## Example
`controllers/User.js`
```js
var baucis = require('baucis');
var mongoose = require('mongoose');
var Schema = mongoose.Schema;

var extend = require('deep-extend');
var ResourceProps = require('../props/Resource.js');
var ResourceController = require('../controllers/Resource.js');

var userUtils = require('../utils/user.js');
var UserProps = extend({}, ResourceProps);

UserProps.viewing = {
  type: [String], // should represent sessionId
  auth: {
    password: 'viewingPassword',
    enabler: 'publicViewing',
    designator: 'viewers',
    resetter: 'resetViewingPassword',
    roles: {
      enabled: {
        read   : true
      }
    }
  },
  reserved: true
};

UserProps.publicViewing = {
  type: Boolean,
  default: true
};

UserProps.viewingPassword = {
  type: String,
  select: false
};

UserProps.resetViewingPassword = {
  type: String,
  select: false
};

UserProps.viewers = {
  type: [{
    type: ObjectId,
    ref: 'User'
  }]
};

UserProps.editing = {
  type: [String], // should represent sessionId
  auth: {
    password: 'editingPassword',
    enabler: 'publicEditing',
    designator: 'editors',
    resetter: 'resetEditingPassword',
    roles: {
      enabled: {
        read   : true,
        write  : true,
        drop   : true
      },
      User: {
        create : true
      }
    }
  },
  reserved: true
};

UserProps.publicEditing = {
  type: Boolean,
  default: false
};

UserProps.editingPassword = {
  type: String,
  select: false
};

UserProps.resetEditingPassword = {
  type: String,
  select: false
};

UserProps.editors = {
  type: [{
    type: ObjectId,
    ref: 'User'
  }],
  init: function (req, res, next) {
    return [userUtils.getId(req, res, next)];
  }
};

var UserSchema = new Schema(UserProps);
var UserModel = mongoose.model('User', UserSchema);
var UserController = baucis.rest('User');

var decorators = require('baucis-decorators');

// decorate controller
decorators.add.call(UserController, [
  'baucis-decorator-auth',  // checks each property for any `auth` fields and adds functionality accordingly
  ResourceController        // `UserController` will inherit all of `ResourceController`'s decorators
]);

/**
 * Expose controller.
 */
module.exports = UserController;

---
_Source: https://npm.io/package/baucis-decorator-auth · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
