# passport-azure-oauth2

> Passport strategy for authenticating with Azure OAuth 2.0 API, with prompt and state support

Latest version **0.1.0** (published 2015-01-21) · 0 weekly downloads

## Install

```sh
npm install passport-azure-oauth2
pnpm add passport-azure-oauth2
yarn add passport-azure-oauth2
bun add passport-azure-oauth2
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.1.0 |
| Published | 2015-01-21 |
| First published | 2015-01-21 |
| Weekly downloads | 0 |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 1 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 15 |
| Author | Andrew Keig |
| Maintainers | airasoul |
| Keywords | azure, oauth2, oauth, passport |

## Links

- npm: https://www.npmjs.com/package/passport-azure-oauth2
- Repository: https://github.com/andrewkeig/passport-azure-oauth2
- Issues: https://github.com/andrewkeig/passport-azure-oauth2/issues
- npm.io page: https://npm.io/package/passport-azure-oauth2

## Dependencies (1)

- [passport-oauth](https://npm.io/package/passport-oauth.md) ^1.0.0

## Alternatives

- [@clerk/clerk-expo](https://npm.io/package/@clerk/clerk-expo.md) — 133.6K weekly downloads
- [@pothos/plugin-authz](https://npm.io/package/@pothos/plugin-authz.md) — 12.4K weekly downloads
- [@bounded-sh/client](https://npm.io/package/@bounded-sh/client.md) — 3.2K weekly downloads
- [@luigi-project/plugin-auth-oauth2](https://npm.io/package/@luigi-project/plugin-auth-oauth2.md) — 2.3K weekly downloads
- [@nocobase/plugin-verification](https://npm.io/package/@nocobase/plugin-verification.md) — 2.0K weekly downloads

## Recent versions

- 0.1.0 (latest) — 2015-01-21

## README

# passport-azure-oauth2

Passport strategy for authenticating with Azure OAuth 2.0 API, with prompt and state support.

[![build status](https://travis-ci.org/AndrewKeig/passport-azure-oauth2.svg)](http://travis-ci.org/AndrewKeig/passport-azure-oauth2)

## Installation

```
npm install passport-azure-oauth2 --save
```

## Usage

Create a module `auth.js`:

```

"use strict";

/*jshint camelcase: false */

var AzureOAuth2Strategy  = require("passport-azure-oauth2");
var jwt 				  = require("jwt-simple");
var config 				  = require("../config");

function AzureOAuthStrategy() {
	this.passport = require("passport");
	
	this.passport.use("provider", new AzureOAuth2Strategy({
	  clientID: config.clientID,
	  clientSecret: config.clientSecret,
	  callbackURL: config.callbackUri,
	  resource: config.resource,
	  tenant: config.tenant,
	  prompt: 'login',
	  state: false
	},
	function (accessToken, refreshtoken, params, profile, done) {
	  var user = jwt.decode(params.id_token, "", true);
	  done(null, user);
	}));

	this.passport.serializeUser(function(user, done) {
		//console.log("profile : ", user);
		done(null, user);
	});

	this.passport.deserializeUser(function(user, done) {
		//console.log("profile : ", user);
		done(null, user);
	});
}

module.exports = new AzureOAuthStrategy();
```

Now plug this in like so:

```

var auth  	= require("./auth"),
var express = require("express")
var app     = express();

app.use(auth.passport.initialize());
app.use(auth.passport.session());

app.get("/login", auth.passport.authenticate("provider", { successRedirect: "/" }));

app.get("/cb", 
    auth.passport.authenticate("provider", { 
    successRedirect: "/", 
    failureRedirect: "/login" }), function (req, res) { res.redirect("/"); });


```

###state

Simply plugin `express-session` to enable session support, and set `state: true` when creating your `AzureOAuthStrategy`

[Recommended] A randomly generated non-reused value that is sent in the request and returned in the response. This parameter is used as a mitigation against cross-site request forgery (CSRF) attacks. For more information, see Best Practices for OAuth 2.0 in Azure AD.


```
var session = require("express-session");

app.use( session({ 
    secret: 'somesecret', 
    resave: true, 
    saveUninitialized : true 
}));

```

###prompt

Simply set `prompt: 'login'` when creating your `AzureOAuthStrategy`

[Optional] Indicate the type of user interaction that is required.
Valid values are:

- login: The user should be prompted to re-authenticate.
- consent: User consent has been granted, but needs to be updated. The user should be prompted to consent. 
- admin_consent: An administrator should be prompted to consent on behalf of all users in their organization.

## Tests


```
npm test
```

## License

[MIT](https://github.com/andrewkeig/joi-contrib/blob/master/LICENSE)

---
_Source: https://npm.io/package/passport-azure-oauth2 · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
