@better-iam/server
v0.2.0
Published
The Better IAM server: the betterIam() factory, tenant provisioning, authorization, events and webhooks, audit, and Node and Fetch HTTP handlers.
Maintainers
Readme
Server
The betterIam factory, tenant provisioning, authenticated management services, authorization, events and webhooks, Node/Fetch handlers, root bootstrap, and audit dispatch.
import { betterIam } from '@better-iam/server';Node.js 22.12+ server runtime; PostgreSQL and SQLite adapters. All packages are ESM with TypeScript declarations. Version 0.1.0 packages are synchronized. The browser client and core do not import server drivers.
Layout
betterIam() in src/index.ts composes small modules that share one ServerContext:
options.tsvalidates configuration;catalog.tsowns the permission catalog;plugins.tsvalidates plugins.context.tsprovides storage helpers (tenants, ancestry, authorities, scoping, owner setup).decisions.tsevaluates policies (including relationships and simulated principals),principals.tsresolves credentials,operations.tswraps every call in the transactional authorization envelope,events.tsrecords chained audit events and drives webhooks and subscribers,observe.tstimes spans, andassertions.tsissues and verifies stateless assertions.api/holds one file per API group;flows.tsholds invitation, linking, and role-assumption flows;lifecycle.tsholds bootstrap, audit-chain backfill, and the retention worker;federation.tsexposes protocol callbacks;http.tsholds the transports.
Configuration, threat-model documentation, and runnable SQLite/PostgreSQL examples are included in the Better IAM source repository. No AWS wire compatibility is claimed. Publication does not grant rights; see LICENSE. Dependencies retain their own licenses.
