# nocms-auth

> nocms auth

Latest version **2.3.0** (published 2018-03-29) · ISC license · 0 weekly downloads

## Install

```sh
npm install nocms-auth
pnpm add nocms-auth
yarn add nocms-auth
bun add nocms-auth
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 2.3.0 |
| Published | 2018-03-29 |
| First published | 2017-10-13 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 1 |
| Unpacked size | 23.6 KB |
| Known vulnerabilities | 0 (+3 in 1 direct dependencies) |
| Install scripts | no |
| GitHub stars | 0 |
| Maintainers | nocms |

## Links

- npm: https://www.npmjs.com/package/nocms-auth
- Repository: https://github.com/miles-no/nocms-auth
- Homepage: https://github.com/miles-no/nocms-auth#readme
- Issues: https://github.com/miles-no/nocms-auth/issues
- npm.io page: https://npm.io/package/nocms-auth

## Dependencies (1)

- [jsonwebtoken](https://npm.io/package/jsonwebtoken.md) ^8.1.0

## Recent versions

- 2.3.0 (latest) — 2018-03-29
- 2.2.2 — 2018-03-28
- 2.2.1 — 2018-03-28
- 2.2.0 — 2018-03-28
- 2.1.0 — 2018-03-23
- 2.0.0 — 2017-12-13
- 1.0.0 — 2017-10-13

## README

# nocms-auth

Auth middleware for NoCMS

[![semantic-release](https://img.shields.io/badge/%20%20%F0%9F%93%A6%F0%9F%9A%80-semantic--release-e10079.svg)](https://github.com/semantic-release/semantic-release)
[![Dependency Status](https://david-dm.org/miles-no/nocms-auth.svg)](https://david-dm.org/miles-no/nocms-auth)
[![devDependencies](https://david-dm.org/miles-no/nocms-auth/dev-status.svg)](https://david-dm.org/miles-no/nocms-auth?type=dev)


## Installation

Install nocms-auth from NPM. 

```
npm install nocms-auth --save
```

## Usage

```
const { readClaims, verifyClaim } = require('nocms-auth');

app.use(cookieParser()); // Only needed if Authorization header is not set
app.use(readClaims(config.tokenSecret, logger));

app.post(['/people/*'], verifyClaim('publisher', logger));

```

## Commit message format and publishing

This repository is published using `semantic-release`, with the default [AngularJS Commit Message Conventions](https://docs.google.com/document/d/1QrDFcIiPjSLDn3EL15IJygNPiHORgU1_OOAqWjiDU5Y/edit).

## API

### readClaims, (tokenSecret, logger)
Read claims from the ``nocms-authenticated`` cookie (requires cookie-parser middleware) or Authorization header. Verifies claims and sets tokenValid, claims and authorizationHeader on req.locals.

### verifyClaim, (claim, logger)
Method to use for ensuring tokenValid and given claim is true. If claim can't be verified, the middleware responds with a 403. Invalid tokens will result in a 401 response.

### assertClaim, (tokenSecret, token, claim)
Method to use for reading a token and asserting a claim. The method returns a promise which will resolve with no params or reject with an error object with a `status`. Status 401 means invalid token, whereas 403 means missing claim.

```js
assertClaim(tokenSecret, token, 'admin')
  .then(() => {
    // I am admin
  })
  .catch((err) => {
    // I am not admin
  });
```

---
_Source: https://npm.io/package/nocms-auth · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
