# ecc-auth

> What is this?

Latest version **1.0.0** (published 2020-07-29) · Apache-2.0 license · 0 weekly downloads

## Install

```sh
npm install ecc-auth
pnpm add ecc-auth
yarn add ecc-auth
bun add ecc-auth
```

## Health

**Score 25/100 (F)** — status: abandoned.

Positive: has types; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2020-07-29 |
| First published | 2020-07-29 |
| Weekly downloads | 0 |
| License | Apache-2.0 |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 1 |
| Unpacked size | 33 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 0 |
| Maintainers | menduz |

## Links

- npm: https://www.npmjs.com/package/ecc-auth
- Repository: https://github.com/menduz/ecc-auth
- Homepage: https://github.com/menduz/ecc-auth#readme
- Issues: https://github.com/menduz/ecc-auth/issues
- npm.io page: https://npm.io/package/ecc-auth

## Dependencies (1)

- [secp256k1](https://npm.io/package/secp256k1.md) ^4.0.2

## Recent versions

- 1.0.0 (latest) — 2020-07-29

## README

# ecc-auth

What is this?

* A library that normalizes the crypto API for browser and Node.js
* A library to sign fetch requests using `secp256k1`
* A middleware to validate those signatures from `express`
* Uses the native `crypto` in the browser and the built in Node.js package

### Install

```bash
npm install --save ecc-auth
```

### Usage to authenticate requests

#### Browser

```ts
import * as ecc from "ecc-auth/browser";
import { ApiClient } from "ecc-auth/api-client";

// generate ephemeral keys
const keys = ecc.generateKeyPair();

// create client instance
const client = new ApiClient("https://my-service.menduz.com", keys, ecc);

// send signed request
await client.fetch("/me");
```

#### Node.js (express)

```ts
import { requireSignature, getContext } from "ecc-auth/middleware";

const publicKeyWhitelist = new Set<string>();

function authenticatePublicKey(request, response, next) {
  const ctx = getContext(request);

  if (publicKeyWhitelist.has(ctx.publicKey)) {
    next();
  } else {
    next("Unauthorized");
  }
}

app.get("/me", requireSignature(), authorizePublicKey, function (req, res) {
  res.send("Hi there!");
});
```

### Usage of the plain ECC functions

```ts
// from Node.js
import * as ecc from "ecc-auth/node";
// from Browser
import * as ecc from "ecc-auth/browser";


// generate keys
const keys = ecc.generateKeyPair();

const payload = toHex("Hi there!");

// sign payload
const sig = await signUint8Array(payload, keys.privateKey);

// validate signature
assert(
  true == (await isSignatureValid(sig.signature, payload, keys.publicKey))
);
```

### Exposed interface

```ts
// both 'ecc-auth/browser' and 'ecc-auth/node' modules expose the same interface

function isSignatureValid(
  signature: Uint8Array,
  message: Uint8Array,
  publicKey: Uint8Array
): Promise<boolean>;
function isSignatureValidHex(
  signatureHex: string,
  messageHex: string,
  publicKeyHex: string
): Promise<boolean>;
function validateRequestSignature(
  signatureHex: string,
  method: string,
  path: string,
  timestamp: string,
  body: string | Uint8Array | void,
  publicKeyHex: string
): Promise<void>;
function generateKeyPair(): Keys;
function getRequestSignature(
  method: string,
  path: string,
  timestamp: string,
  body: string | Uint8Array | void,
  privatekey: Uint8Array
): Promise<Signature>;
function fromHex(hexString: string): Uint8Array;
function toHex(bytes: Uint8Array): string;
function signString(message: string, key: Uint8Array): Promise<Signature>;
function signUint8Array(
  msgUint8: Uint8Array,
  key: Uint8Array
): Promise<Signature>;
function sha256string(message: string): Promise<string>;
function sha256(msgUint8: Uint8Array): Promise<string>;
```

---
_Source: https://npm.io/package/ecc-auth · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
