# hapi-auth-basic

> Basic authentication plugin

Latest version **5.0.0** (published 2017-11-26) · BSD-3-Clause license · 0 weekly downloads

> **Deprecated.** This package is deprecated.

## Install

```sh
npm install hapi-auth-basic
pnpm add hapi-auth-basic
yarn add hapi-auth-basic
bun add hapi-auth-basic
```

## Health

**Score 10/100 (F)** — status: deprecated.

Negative: deprecated.

## Facts

| | |
|---|---|
| Version | 5.0.0 |
| Published | 2017-11-26 |
| First published | 2014-01-08 |
| Weekly downloads | 0 |
| License | BSD-3-Clause |
| TypeScript types | separate (@types/hapi-auth-basic) |
| Module format | CommonJS |
| Node | >=8.9.0 |
| Dependencies | 2 |
| Known vulnerabilities | 0 (+1 in 1 direct dependencies) |
| Install scripts | no |
| GitHub stars | 147 |
| Maintainers | mtharrison, stongo, biant, hueniverse, wyatt, marsup, nlf |
| Keywords | hapi, plugin, auth, basic |

## Links

- npm: https://www.npmjs.com/package/hapi-auth-basic
- Repository: https://github.com/hapijs/hapi-auth-basic
- Homepage: https://github.com/hapijs/hapi-auth-basic#readme
- Issues: https://github.com/hapijs/hapi-auth-basic/issues
- npm.io page: https://npm.io/package/hapi-auth-basic

## Dependencies (2)

- [boom](https://npm.io/package/boom.md) 7.x.x
- [hoek](https://npm.io/package/hoek.md) 5.x.x

## Alternatives

- [@clerk/clerk-expo](https://npm.io/package/@clerk/clerk-expo.md) — 133.6K weekly downloads
- [@pothos/plugin-authz](https://npm.io/package/@pothos/plugin-authz.md) — 12.4K weekly downloads
- [@bounded-sh/client](https://npm.io/package/@bounded-sh/client.md) — 3.2K weekly downloads
- [@luigi-project/plugin-auth-oauth2](https://npm.io/package/@luigi-project/plugin-auth-oauth2.md) — 2.3K weekly downloads
- [@nocobase/plugin-verification](https://npm.io/package/@nocobase/plugin-verification.md) — 2.0K weekly downloads

## Recent versions

- 5.0.0 (latest) — 2017-11-26
- 4.2.0 — 2016-05-19
- 4.1.0 — 2015-11-17
- 4.0.0 — 2015-11-04
- 3.0.0 — 2015-07-04
- 2.0.0 — 2014-12-10
- 2.0.0-rc1 — 2014-11-26
- 1.1.1 — 2014-08-04
- 1.1.0 — 2014-06-12
- 1.0.2 — 2014-05-20
- 1.0.1 — 2014-03-21
- 1.0.0 — 2014-01-08

## README

### hapi-auth-basic

[![Build Status](https://secure.travis-ci.org/hapijs/hapi-auth-basic.svg)](http://travis-ci.org/hapijs/hapi-auth-basic)

Lead Maintainer: [Matt Harrison](https://github.com/mtharrison)

Basic authentication requires validating a username and password combination. The `'basic'` scheme takes the following options:

- `validate` - (required) a user lookup and password validation function with the signature `[async] function(request, username, password, h)` where:
    - `request` - is the hapi request object of the request which is being authenticated.
    - `username` - the username received from the client.
    - `password` - the password received from the client.
    - `h` - the response toolkit.
    - Returns an object `{ isValid, credentials, response }` where:
        - `isValid` - `true` if both the username was found and the password matched, otherwise `false`.
        - `credentials` - a credentials object passed back to the application in `request.auth.credentials`.
        - `response` - Optional. If provided will be used immediately as a takeover response. Can be used to redirect the client, for example. Don't need to provide `isValid` or `credentials` if `response` is provided
    - Throwing an error from this function will replace default `Boom.unauthorized` error
    - Typically, `credentials` are only included when `isValid` is `true`, but there are cases when the application needs to know who tried to authenticate even when it fails (e.g. with authentication mode `'try'`).
- `allowEmptyUsername` - (optional) if `true`, allows making requests with an empty username. Defaults to `false`.
- `unauthorizedAttributes` - (optional) if set, passed directly to [Boom.unauthorized](https://github.com/hapijs/boom#boomunauthorizedmessage-scheme-attributes) if no custom `err` is thrown. Useful for setting realm attribute in WWW-Authenticate header. Defaults to `undefined`.

```javascript
const Bcrypt = require('bcrypt');
const Hapi = require('hapi');

const users = {
    john: {
        username: 'john',
        password: '$2a$10$iqJSHD.BGr0E2IxQwYgJmeP3NvhPrXAeLSaGCj6IR/XU5QtjVu5Tm',   // 'secret'
        name: 'John Doe',
        id: '2133d32a'
    }
};

const validate = async (request, username, password, h) => {

    if (username === 'help') {
        return { response: h.redirect('https://hapijs.com/help') };     // custom response
    }

    const user = users[username];
    if (!user) {
        return { credentials: null, isValid: false };
    }

    const isValid = await Bcrypt.compare(password, user.password);
    const credentials = { id: user.id, name: user.name };

    return { isValid, credentials };
};

const main = async () => {

    const server = Hapi.server({ port: 4000 });

    await server.register(require('hapi-auth-basic'));

    server.auth.strategy('simple', 'basic', { validate });
    server.auth.default('simple');

    server.route({
        method: 'GET',
        path: '/',
        handler: function (request, h) {

            return 'welcome';
        }
    });

    await server.start();

    return server;
};

main()
.then((server) => console.log(`Server listening on ${server.info.uri}`))
.catch((err) => {

    console.error(err);
    process.exit(1);
});
```

---
_Source: https://npm.io/package/hapi-auth-basic · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
