# hapi-auth-sns

> AWS SNS Authentication

Latest version **2.0.0** (published 2023-02-02) · MIT license · 0 weekly downloads

## Install

```sh
npm install hapi-auth-sns
pnpm add hapi-auth-sns
yarn add hapi-auth-sns
bun add hapi-auth-sns
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 2.0.0 |
| Published | 2023-02-02 |
| First published | 2022-08-07 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 4 |
| Unpacked size | 10.3 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 2 |
| Maintainers | devin_stewart |
| Keywords | AWS, SNS, authentication, plugin, hapi |

## Links

- npm: https://www.npmjs.com/package/hapi-auth-sns
- Repository: https://github.com/devinstewart/hapi-auth-sns
- Homepage: https://github.com/devinstewart/hapi-auth-sns#readme
- Issues: https://github.com/devinstewart/hapi-auth-sns/issues
- npm.io page: https://npm.io/package/hapi-auth-sns

## Dependencies (4)

- [joi](https://npm.io/package/joi.md) ^17.6.0
- [@hapi/boom](https://npm.io/package/@hapi/boom.md) ^10.0.0
- [@hapi/hoek](https://npm.io/package/@hapi/hoek.md) ^11.0.2
- [sns-payload-validator](https://npm.io/package/sns-payload-validator.md) ^2.0.1

## Alternatives

- [@clerk/clerk-expo](https://npm.io/package/@clerk/clerk-expo.md) — 133.6K weekly downloads
- [@pothos/plugin-authz](https://npm.io/package/@pothos/plugin-authz.md) — 12.4K weekly downloads
- [@bounded-sh/client](https://npm.io/package/@bounded-sh/client.md) — 3.2K weekly downloads
- [@luigi-project/plugin-auth-oauth2](https://npm.io/package/@luigi-project/plugin-auth-oauth2.md) — 2.3K weekly downloads
- [@nocobase/plugin-verification](https://npm.io/package/@nocobase/plugin-verification.md) — 2.0K weekly downloads

## Recent versions

- 2.0.0 (latest) — 2023-02-02
- 1.1.0 — 2022-09-29
- 1.0.1 — 2022-08-09
- 1.0.0 — 2022-08-07

## README

# hapi Auth Plugin for AWS SNS
Plugin for [hapi](https://hapi.dev) to easily setup an [auth strategy](https://hapi.dev/api/?v=20.2.2#-serverauthstrategyname-scheme-options) that validates an [AWS SNS](https://docs.aws.amazon.com/sns/latest/dg/welcome.html) payload using the [sns-payload-validator](https://www.npmjs.com/package/sns-payload-validator).

[![Coverage Status](https://coveralls.io/repos/github/devinstewart/hapi-auth-sns/badge.svg?branch=main)](https://coveralls.io/github/devinstewart/hapi-auth-sns?branch=main)
[![GitHub Workflow Status](https://github.com/devinstewart/hapi-auth-sns/actions/workflows/ci-plugin.yml/badge.svg?branch=main)](https://github.com/devinstewart/hapi-auth-sns/actions?query=workflow%3Aci+branch%3Amain)
[![Maintainability Rating](https://sonarcloud.io/api/project_badges/measure?project=devinstewart_hapi-auth-sns&metric=sqale_rating)](https://sonarcloud.io/summary/overall?id=devinstewart_hapi-auth-sns)
[![Security Rating](https://sonarcloud.io/api/project_badges/measure?project=devinstewart_hapi-auth-sns&metric=security_rating)](https://sonarcloud.io/summary/overall?id=devinstewart_hapi-auth-sns)
[![Reliability Rating](https://sonarcloud.io/api/project_badges/measure?project=devinstewart_hapi-auth-sns&metric=reliability_rating)](https://sonarcloud.io/summary/overall?id=devinstewart_hapi-auth-sns)
## Installing
```bash
npm install --save hapi-auth-sns
```
**Please note:** While `SignatureVersion` 1 is the default, on 2022-09-19 [AWS announced](https://aws.amazon.com/blogs/security/sign-amazon-sns-messages-with-sha256-hashing-for-http-subscriptions/) the ability to set topics with `SignatureVersion` 2. Starting with version `1.1.0` of this plugin, `SignatureVersion` 1 and 2 are supported.

## Getting Started
```js
const Hapi = require('hapi');
const Sns = require('hapi-auth-sns');

const init = async () => {

    const server = Hapi.server({
        port: 3000,
        host: '0.0.0.0'
    });

    // Register the plugin
    await server.register(Sns);

    // Declare an authentication strategy using the sns scheme.
    server.auth.strategy('mySnsStrategy', 'sns');

    // Add a route that requires authentication.
    server.route({
        method: 'POST',
        path: '/',
        config: {
            auth: {
                strategy: 'mySnsStrategy',
                scope: 'myTopic' // optional
            },
        },
        handler: (request, h) => {

            // Make sure the message is a notification, not a subscription confirmation.
            if (request.payload.Type === 'Notification') {
                return `The message from myTopic is: ${request.payload.Message}`;
            }

            return 'This is a subscription confirmation message.';
        }

        await server.start();
        console.log('Server running on %s', server.info.uri);
    });
};

init();
```

## Scopes
The scope in the credentials is set to the topic name, derived from the `TopicArn` in the payload.

To limit the route to a single topic, set the `scope` option to the topic name:
```js
auth: {
    strategy: 'mySnsStrategy',
    scope: 'myTopic'
}
```

To allow multiple topics, set the `scope` option to an array of topic names:
```js
auth: {
    strategy: 'mySnsStrategy',
    scope: ['myTopic1', 'myTopic2']
}
```

To allow all topics, omit the `scope` option:
```js
auth: {
    strategy: 'mySnsStrategy'
}
```

## Options
There are four options available for the sns strategy:
- `autoSubscribe` - A message type of `SubscriptionConfirmation` automatically subscribes the route to the topic after validation, default `true`.
- `autoResubscribe` - A message type of `UnsubscribeConfirmation` automatically resubscribes the route to the topic after validation, default `true`.
- `useCache` - The plugin uses a cache to store the certificate for each topic. This is enabled by default, but can be disabled if you don't want to use the cache. If disabled, the certificate will be fetched from the SNS service for each request.
- `maxCerts` - The maximum number of certificates to store in the cache. This is only used if `useCache` is enabled. The default is `5000`.

All settings can be changed when declaring the strategy:
```js
server.auth.strategy('mySnsStrategy', 'sns', {
    autoSubscribe: false,
    autoResubscribe: false,
    useCache: true,
    maxCerts: 100
});
```

## Additional Information
The `request.payload` will have the following properties:
- `Type` - The message type: `Notification`, `SubscriptionConfirmation` or `UnsubscribeConfirmation`.
- `MessageId` - A uuid provided by the SNS service for each message.
- `Token` - The token that must be passed to the `SubscribeURL` to confirm the subscription when the message type is `SubscriptionConfirmation` or `UnsubscribeConfirmation`.
- `TopicArn` - The ARN of the topic the message was sent from.
- `Subject` - The subject of the message when the message type is `Notification`. This is not present if a Subject was not provided when the message was published.
- `Message` - The message body when the message type is `Notification`.
- `Timestamp` - The time the message was sent.
- `SignatureVersion` - The version of the signature algorithm used to sign the message. Defaults to `1`, can also be `2`.
- `Signature` - The signature of the message used to verify the message integrity.
- `SigningCertURL` - The URL of the certificate used to sign the message.
- `SubscribeURL` - The URL used to subscribe the route when the message type is `SubscriptionConfirmation` or `UnsubscribeConfirmation`.
- `UnsubscribeURL` - The URL used to unsubscribe the route when the message type is `Notification`.

Due to how payload validation works, `request.auth.credentials.sns` will be set to `true` if payload is valid.  However, it is not used by the plugin.

## Acknowledgements
The format of the code was adapted from the [@hapi/jwt](https://www.npmjs.com/package/@hapi/jwt) module, [BSD-3-Clause](https://github.com/hapijs/jwt/blob/master/LICENSE.md), which is maintained by the fine folks in the [hapijs community](https://github.com/hapijs).

---
_Source: https://npm.io/package/hapi-auth-sns · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
