# urn-schema

> URN schema validation

Latest version **0.2.1** (published 2016-08-06) · 0 weekly downloads

## Install

```sh
npm install urn-schema
pnpm add urn-schema
yarn add urn-schema
bun add urn-schema
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.2.1 |
| Published | 2016-08-06 |
| First published | 2016-08-02 |
| Weekly downloads | 0 |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 2 |
| Known vulnerabilities | 0 (+1 in 1 direct dependencies) |
| Install scripts | no |
| Maintainers | nfour |
| Keywords | acl, schema, urn, access, control |

## Links

- npm: https://www.npmjs.com/package/urn-schema
- npm.io page: https://npm.io/package/urn-schema

## Dependencies (2)

- [lutils](https://npm.io/package/lutils.md) ^1.1.0
- [transposer](https://npm.io/package/transposer.md) ~0.3.0

## Alternatives

- [@regle/core](https://npm.io/package/@regle/core.md) — 47.0K weekly downloads
- [typeof-arguments](https://npm.io/package/typeof-arguments.md) — 12.5K weekly downloads
- [@lokalise/projects-engine-contracts](https://npm.io/package/@lokalise/projects-engine-contracts.md) — 978 weekly downloads
- [@osjwnpm/nam-laboriosam-quibusdam](https://npm.io/package/@osjwnpm/nam-laboriosam-quibusdam.md) — 70 weekly downloads
- [@oridune/validator](https://npm.io/package/@oridune/validator.md) — 16 weekly downloads

## Recent versions

- 0.2.1 (latest) — 2016-08-06
- 0.2.0 — 2016-08-06
- 0.1.2 — 2016-08-03
- 0.1.1 — 2016-08-02
- 0.1.0 — 2016-08-02

## README

# URN Schema

This library handles URN schemas, similar to AWS ARN's, useful for access control.

Features:
- [x] Variable interpolation `urn:${some.dataset}`
- [x] Wildcarding `urn:*`
- [x] Precompilation for performance
- [x] Uri validation `urn:this/${is.a}/*/uri?with&a&query`
- [x] ACL's
- [x] Conforms to [URN](https://en.wikipedia.org/wiki/Uniform_Resource_Name)

```js
import UrnSchema, { UriValidator } from 'urn-schema'

const schema = new UrnSchema('version:method:scope:uri', {
    uri: UriValidator,
})

const acl = schema.createAcl({
    group_a: [
        "urn:1.0:POST:testing:products/*/items/*"
    ]
})

acl.validate('group_a', {
    version : '1.0',
    method  : 'POST',
    scope   : 'testing',
    uri     : 'products/22/items'
}) // returns { valid: true, group: 'group_a' }

acl.validate('group_a', {
    version : '2.0',
    method  : 'GET',
    scope   : 'testing',
    uri     : 'products/22/items'
}) // returns { valid: false, group: 'group_a' }

```

In the basic example above we have defined a schema which matches predefined properties, including parsing the `uri` appropriately.

Below is a more advanced example.

```js
const acl = schema.createAcl({
    group_a: [
        "urn:${versions}:GET:${scopes}:products/${user['!~validIds~!']}/*?direction&order"
    ]
})

const data = {
    versions: [ '1.0', '2.0' ],
    scopes: [ 'testing', 'staging' ],
    user: {
        "!~validIds~!": [ 22, 24, 77 ]
    }
}

acl.validate('group_a', {
    version : '2.0',
    method  : 'GET',
    scope   : 'testing',
    uri     : 'products/22/items?order=size'
}, data) // returns { valid: true, group: 'group_a' }
```

In the above example the variables defined in `group_a`'s first urn are interpolated from the `data` object.

These uri's would also pass:
- `products/24/`
- `products/27/something?direction=asc`

And so too would version `1.0` and scope `staging`.

It's easy to parse a full URL into something you can use against the schema.
Imagine the below `originalUrl` is `/2.0/testing/products/22`.

```js
app.use((req, res, next) => {
    const { method, originalUrl, auth } = req

    // Take off the first 2 parts
    let [ version, scope, ...uri ] = originalUrl
        .replace(/^\/|\/$/g, '') // Remove trailing & leading slashes
        .split('/')

    uri = uri.join('/') // Join it back up

    const aclCheck = acl.validate(auth.scope, {
        version, scope, method, uri
    })

    if ( aclCheck.valid )
        return next()

    return next( new ForbiddenError("Permission denied!!!") )
})

```

### Interpolation Mechanics

When a variable is interpolated, the type matters.

- If `${some.data}` resolves to an array `[1, 2]`, then the value can match either of them, as a string comparison
- If `${some.data}` resolves to any other type, it will be stringified and compared against the value

---
_Source: https://npm.io/package/urn-schema · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
