npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@dofe/sso-nestjs

v0.1.72

Published

NestJS integration for sso.dofe.ai internal service APIs.

Readme

@dofe/sso-nestjs

NestJS integration for sso.dofe.ai internal service APIs.

Install

pnpm add @dofe/sso-nestjs @dofe/sso-node @nestjs/axios

Usage

import { Module } from '@nestjs/common';
import { ConfigService } from '@nestjs/config';
import { SsoClientModule } from '@dofe/sso-nestjs';

@Module({
  imports: [
    SsoClientModule.forRootAsync({
      inject: [ConfigService],
      useFactory: (config: ConfigService) => ({
        baseUrl: config.getOrThrow('SSO_INTERNAL_API_URL'),
        internalSecret: config.getOrThrow('INTERNAL_API_SECRET'),
        serviceName: 'agents.dofe.ai',
      }),
    }),
  ],
})
export class AppModule {}
import { Injectable } from '@nestjs/common';
import { SsoClientService } from '@dofe/sso-nestjs';

@Injectable()
export class ExampleService {
  constructor(private readonly sso: SsoClientService) {}

  async loadUser(userId: string) {
    return this.sso.getUser(userId);
  }
}

For low-level access, use the underlying @dofe/sso-node client:

await this.sso.client.users.get(userId);
await this.sso.client.teams.getMembers(teamId);
await this.sso.client.permissions.check({ userId, teamId, permission });

For migration from existing local SSO clients, SsoClientService also exposes flat helper methods:

await this.sso.getUser(userId);
await this.sso.getUserTeams(userId);
await this.sso.checkPermission(userId, permission, teamId);
await this.sso.getTeamMembers(teamId);
await this.sso.getUserTeamRole(teamId, userId);
await this.sso.getTenantMembers(tenantId);
await this.sso.getUserTenantRole(tenantId, userId);

For permission checks, prefer SsoPermissionService over hand-written HTTP clients in consuming projects:

import { Injectable } from '@nestjs/common';
import { SsoPermissionService } from '@dofe/sso-nestjs';

@Injectable()
export class PermissionService {
  constructor(private readonly ssoPermissions: SsoPermissionService) {}

  checkLoopPermission(userId: string, action: string, teamId?: string) {
    return this.ssoPermissions.checkModulePermission(userId, 'vibecoding', 'loops', action, teamId);
  }
}

AuthGuard base

Consumer AuthGuards extend DofeSsoAuthGuardBase, delegating the standard SSO token-verify / blacklist / local-user / admin flow to the SDK and keeping only project-specific logic in SsoAuthGuardHooks + a subclass.

import { Injectable } from '@nestjs/common';
import {
  DofeSsoAuthGuardBase,
  type SsoAuthGuardHooks,
  type SsoAuthenticatedRequest,
} from '@dofe/sso-nestjs';

@Injectable()
export class MyAuthHooks implements SsoAuthGuardHooks {
  async resolveLocalUser(ssoSub, claims) {
    /* find/create local user */
  }
  resolveIsAdmin(localUser, claims) {
    return localUser.isAdmin;
  }
  async isBlacklisted?(token) {
    /* optional token blacklist */
  }
  async shouldBypass?(req, ctx) {
    /* optional: health/internal bypass */
  }
}

@Injectable()
export class AuthGuard extends DofeSsoAuthGuardBase {
  /* project-specific checks only */
}

Dev-only bypass (e.g. MODE_USER_ID) is intentionally NOT in the base — implement it in your subclass or shouldBypass hook.

OIDC Relying Party

SsoOidcRelyingPartyModule + SsoOidcRelyingPartyService own the PKCE authorize / callback / exchange / refresh / logout flow. Production must inject a Redis-backed state store (the default InMemoryStateStore loses state on restart and does not share across instances):

import {
  SsoOidcRelyingPartyModule,
  OIDC_RP_STATE_STORE,
  createRedisOidcStateStore,
} from '@dofe/sso-nestjs';

SsoOidcRelyingPartyModule.forRootAsync({
  inject: [ConfigService, RedisService],
  useFactory: (config, redis) => ({
    clientId: config.getOrThrow('SSO_CLIENT_ID'),
    clientSecret: config.getOrThrow('SSO_CLIENT_SECRET'),
    issuerUrl: config.getOrThrow('SSO_ISSUER'),
    internalIssuerUrl: config.get('SSO_INTERNAL_API_URL'),
    redirectPath: '/auth/oidc/callback',
    successPath: '/auth/oidc/success',
    serviceName: 'agents.dofe.ai',
  }),
  stateStore: {
    provide: OIDC_RP_STATE_STORE,
    inject: [RedisService],
    useFactory: (redis) => createRedisOidcStateStore(redis, { keyPrefix: 'dofe:oidc:' }),
  },
});

createRedisOidcStateStore is driver-agnostic (duck-typed ioredis surface) — the SDK does NOT depend on any redis driver; pass your app's existing client.

OIDC helpers (DOFE_RF_COOKIE, classifyRefreshError, resolveOidcUrls, isSecureCookieRequired, getCookieDomain, getDefaultCookieOptions) are framework-free and can be imported on their own.

Boundary

This package wraps @dofe/sso-node with a Nest module and HttpService fetcher. It does not include Redis event subscribers, Prisma, migrations, seeds, or database connection logic.