# saml-sso-node

> SAML Authentication library using passport

Latest version **0.0.1** (published 2023-09-08) · ISC license · 0 weekly downloads

## Install

```sh
npm install saml-sso-node
pnpm add saml-sso-node
yarn add saml-sso-node
bun add saml-sso-node
```

## Health

**Score 20/100 (F)** — status: abandoned.

Positive: has types; no vulnerabilities.

Warnings: low downloads; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.0.1 |
| Published | 2023-09-08 |
| First published | 2023-09-08 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 10 |
| Unpacked size | 38.9 KB |
| Known vulnerabilities | 0 (+1 in 1 direct dependencies) |
| Install scripts | no |
| Author | Goutham N |
| Maintainers | goutham-flip |

## Links

- npm: https://www.npmjs.com/package/saml-sso-node
- npm.io page: https://npm.io/package/saml-sso-node

## Dependencies (10)

- [pg](https://npm.io/package/pg.md) ^8.11.0
- [express](https://npm.io/package/express.md) ^4.18.2
- [ts-node](https://npm.io/package/ts-node.md) ^10.9.1
- [passport](https://npm.io/package/passport.md) ^0.6.0
- [pg-hstore](https://npm.io/package/pg-hstore.md) ^2.3.4
- [sequelize](https://npm.io/package/sequelize.md) ^6.32.0
- [passport-saml](https://npm.io/package/passport-saml.md) ^3.2.4
- [express-session](https://npm.io/package/express-session.md) ^1.17.3
- [passport-azure-ad](https://npm.io/package/passport-azure-ad.md) ^4.3.5
- [@aws-sdk/client-secrets-manager](https://npm.io/package/@aws-sdk/client-secrets-manager.md) ^3.354.0

## Recent versions

- 0.0.1 (latest) — 2023-09-08

## README

# Configuration

## AWS Configure

- Local aws cli login is required and the user who's logged in he should have the aws secert manager permission.
  > Note: `AWS_REGION` variable is required in the env file.

## Environment

- `.env.example` file is provided for variable references please check and create the same.

## Database

- Default database: `postgres`

- For other databases refer below link.

  [Sequelize Link](https://sequelize.org/docs/v6/other-topics/dialect-specific-things)

- You have the seed the idps data to database.

## How to use

> Middleware `IDPAuthenticationMW` is used to authenticate route(s) using Single Sign-On (SSO) of multiple IDP Services.

- Create IDP Configuration in AWS Secret Manager. (Admin UI can be used to create this)

- Store the `secret_name` in database. (If Admin UI is used, this will be created automatically)

- Import and include the middleware (`IDPAuthenticationMW`) before the controller middleware.
- Payload is required and can be passed in query params or path params or in the request body.

  Example:

  ```js
  const data = {
    idp: "string",
    tenantId: "string",
  };

  app.get("/auth/login", IDPAuthenticationMW, function (req, res) {
    // existing code of authentication...
  });
  ```

# SSO Configuration

## Microsoft

- Use the below links to create tenant, register application and to create user flows.

  [Create Tenant](https://learn.microsoft.com/en-us/azure/active-directory-b2c/tutorial-create-tenant)

  [Register Web application](https://learn.microsoft.com/en-us/azure/active-directory-b2c/tutorial-register-applications?tabs=app-reg-ga)

  [Create User flow](https://learn.microsoft.com/en-us/azure/active-directory-b2c/tutorial-create-user-flows?pivots=b2c-user-flow)
    
    > Note: Creating all the above things are mandatory.

- Custom token generation process should be inside redirect url route.

  Eg. 'GET: /callback/uri' route.

## Okta

- Login to Okta (developers credentials) and create an application and add required configurations to it and add users to the application.

  [Reference Link](https://help.okta.com/en-us/Content/Topics/Apps/Apps_App_Integration_Wizard_SAML.htm)

- 'POST: /callback/uri' - as mentioned in the okta's official documentation redirect url should be POST method, and returns it will pass the user's information in the response, here we can implement or use the custom token generation process.

  ![Reference Image](okta_edit_config.png)

# Publish as package

[index.ts](index.ts) - use this file to rename the middleware.

### Steps to publish

- Execute below command to login to npm registry.

  ```sh
  npm login
  ```

- package.json file changes.

  - Update the `version` number.

  - Change the `private` key as per your requirement. (optional)

  - `name` can be changed as per your requirement. (optional)

  - Update/change all the project information in the package.json file.

- Build the project.

  ```sh
  npm run build
  ```

- Publish commad.

  ```sh
  npm publish --access public
  ```

---
_Source: https://npm.io/package/saml-sso-node · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
