shuttle-access v3.1.1
shuttle-access
Package for use in JavaScript applications to integrate with Shuttle.Access back-end.
npm install shuttle-accessInitialization
Create a new instance of Access:
import Access from 'shuttle-access';
var access = new Access('http://access-api-url');You may also specify an options argument containing the following:
| Option | Default | Description | 
|---|---|---|
| storage | localStorage | A storage mechanism for the usernameandtokenvalues used for authentication.  Must containgetItem(name),setItem(name, value), andremoveItem(name)functions. | 
import Access from 'shuttle-access';
var access = new Access('http://access-api-url', { 
    storage: {
        getItem: function(name) {},
        setItem: function(name, value) {},
        removeItem: function(name) {}
    }
});Next we need to initialize the istance:
access.initilize(); // returns promiseThis will retrieve all the anonymous permissions from the /permissions/anonymous endpoint and add them as type anonymous.  The endpoint can also return an isUserRequired property on the response.  If true then there are no users registered.
Should the storage contain a token then a shuttle-access will attempt to create a session by posting the token to the /sessions endpoint.
Login
access.login(credentials); // returns promisePerforms an explicit login by using the specified credentials which should contain either username and password, or token.  The session-creation will be attempted by sending a POST to the /sessions endpoint using the following JSON body:
{
    username: credentials.username,
    password: credentials.password,
    token: credentials.token
}A login expects the following response from the POST to the /sessions endpoint:
{
	registered: (boolean), // true when session registered; else false
	username: (string), // returns the username associated with the session
	token: (string), // a session token that is specific to the server 
	permissions: ['access://permission-on', 'another', ...]
}If registered is true then the username and token will be set on the storage for future reference.  Each permission will be stored as type user.  In addition the username and token properties on the access instance will also be set.
Logout
access.logout();The username and token properties on the access as well as the storage instances.
Permissions
Permissions are unique. The permissions may be accessed using the following methods:
| Method | Arguments | Description | 
|---|---|---|
| hasPermission | permission | Returns trueif the permission is in theaccessinstance; elsefalse | 
| removePermission | permission | Removes the given permission, if found, from the accessinstance. | 
| addPermission | type, permission | The typeis a grouping mechanism and thepermissionstill has to be unique. | 
| removePermissions | type | Remove all permissions of the given type. | 
Login status
var status = access.loginStatus;Returns:
| Value | Description | 
|---|---|
| user-required | When the /permissions/anonymouscalled returnedisUserRequired. | 
| not-logged-in | When there is no tokenvalue. | 
| logged-in | When there is a tokenvalue. |