# ciphertoken

> Ciphered accessToken management

Latest version **0.9.5** (published 2014-11-25) · MIT license · 0 weekly downloads

## Install

```sh
npm install ciphertoken
pnpm add ciphertoken
yarn add ciphertoken
bun add ciphertoken
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.9.5 |
| Published | 2014-11-25 |
| First published | 2014-11-25 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=0.10.26 |
| Dependencies | 1 |
| Known vulnerabilities | 0 (+2 in 1 direct dependencies) |
| Install scripts | no |
| GitHub stars | 4 |
| Author | Jonas Da Cruz |
| Maintainers | luismesas |

## Links

- npm: https://www.npmjs.com/package/ciphertoken
- Repository: https://github.com/IGZjonasdacruz/ciphertoken
- Issues: https://github.com/IGZjonasdacruz/ciphertoken/issues
- npm.io page: https://npm.io/package/ciphertoken

## Dependencies (1)

- [debug](https://npm.io/package/debug.md) ~0.7.4

## Recent versions

- 0.9.5 (latest) — 2014-11-25
- 0.0.4 — 2014-11-25

## README

--WORK IN PROGRESS--

cipherToken
===========

A method to create ciphered accessToken based on the following principles:
* must include id information.
* must include expiration information.
* must be a designed token to transport, but not to store it.

## NodeJS


### Require

```js
var cipherToken = require('cipherToken');
```

### Usage

cipherToken is designed to be used as a module.

Tokens are created this way

```js
cipherToken.createToken(settings, user_id, session_id, data, function(err, token){});
```


and can be decoded back to a more readable state with


```js
cipherToken.getTokenSet(settings, token, function(err, tokenSet){});
```


#### Settings

Settings is a hash with the following properties

- __cipherKey__ : (required) used to cipher the accessToken
- __firmKey__ : (required) used to firm the accessToken
- __tokenExpirationMinutes__ : minutes of accessToken life (__90__ minutes by default)
- __cipherAlgorithm__ : algorithm used to cipher the token (__aes-256-cbc__ by default)
- __hmacAlgorithm__ : algorithm used to build the hmac (__md5__ by default)
- __hmacDigestEncoding__ : encoding used in the outbound of the hmac digest (__hex__ by default)
- __plainEncoding__ : encoding used in the data content in the token (__utf8__ by default)
- __tokenEncoding__ : encoding used in the token format (__base64__ by default)
- __enableSessionId__ : sessionId of an accessToken, can be preset at accessToken creation

Settings must be passed to cipherToken in each call. Only cipherKey and firmKey are required.


### Method: createToken

```js
cipherToken.createToken(settings, user_id, session_id, data, function(err, token){});
```

To create a token the first thing you need to do is to define your settings.
UserId can be an username or any other thing you use to identify your clients.
SessionId is only when you want to create a token associated to the same session of another token (usually near expiration).
SessionId can be null.
Data is to encode the payload you want to travel with the token.

cipherToken.createToken expects a callback in the error-result form.



### Method: getTokenSet

```js
cipherToken.getTokenSet(settings, token, function(err, tokenSet){});
```

Same settings of creation must be provided in order to decode the token.

tokenSet has the following properties

- userId: the same as the provided one
- expiresAtTimestamp: at creation, gets the actual time and add to it the time expiration to calculate when will the token expire.
Cipher token doesn't care if the token has expired or not.
- data: same as provided
- sessionId: (if enabled) random the first time, after that previous one can be used

### Example

```js
var cipherToken = require('cipherToken');

var settings = {
    cipherKey: 'myCipherKey123',
    firmKey:  'myFirmKey123'
};

var userId = 'John Spartan';
var data = 'validData';

cipherToken.createToken(settings, userId, null, data, doWhateverYouWantWithYourToken);
function doWhateverYouWantWithYourToken(err, token){

}

cipherToken.getTokenSet(settings, validToken, function(err, tokenSet){
    console.log(tokenSet.userId);
    console.log(tokenSet.data);
    console.log(tokenSet.expiresAtTimestamp);
});

```

---
_Source: https://npm.io/package/ciphertoken · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
