OpenID Connect Resource Server Authentication for Node.js
- OAuth 2.0 Bearer Token Usage (RFC 6750)
- JWT Access Token Validation (Specification pending)
- Issuer discovery (OpenID Connect Discovery)
- Dynamic key rotation (OpenID Connect Core)
- Multiple issuer support
- Scope validation
- Allow and deny access by "iss", "aud", and "sub" claims
$ npm install @solid/oidc-rs
const ResourceServer = require('@solid/oidc-rs')
ResourceServer maintains a cache of provider metadata and JSON Web Keys for verifying signatures. Provider discovery and acquisition of keys takes place when a JWT access token is decoded. The provider metadata and JWK Set are cached in memory. Therefore no configuration is required.
const rs = new ResourceServer()
The provider cache can be serialized and persisted, then restored like so:
const providers = require('./providers.json')
ResourceServer.from({providers}).then(rs => /* ... */)
const app = express()
app.use(rs.authenticate(options))
app.get('/endpoint', rs.authenticate(options), (req, res, next) => {})
No configuration is required in order to start using this middleware. All options are optional.
rs.authenticate({
realm: 'user',
scopes: ['foo', 'bar'],
allow: {
issuers: ['https://forge.anvil.io'],
audience: ['clientid1', 'clientid2'],
subjects: ['userid1', 'userid2', 'useridn']
},
deny: { // probably want to use either allow or deny, but not both
issuers: ['https://forge.anvil.io'],
audience: ['clientid1', 'clientid2'],
subjects: ['userid1', 'userid2', 'useridn']
},
handleErrors: false, // defaults to true
tokenProperty: 'token',
claimsProperty: 'claims'
})
realm
– Value of "realm" parameter to use in WWW-Authenticate challenge header.scopes
– Array of scope values required to access this resource.allow
– Object with arrays of allowed issuers, audience and subjects.deny
– Object with arrays of restricted issuers, audience and subjects.handleErrors
– When set to false, error conditions will result in a call tonext()
, passing control to the application's error handling.tokenProperty
– Name of property onreq
to assign decoded JWT object. The property will not be set unless defined.claimsProperty
– name of property onreq
to assign verified JWT claims. Defaults to "claims".
$ npm test
Copyright (c) 2016 Anvil Research, Inc. Copyright (c) 2017-2019 The Solid Project