@ossy/authentication
v3.5.1
Published
Authentication feature package - sign-in, sign-up, and invitation pages for Ossy apps
Readme
@ossy/authentication
Authentication feature package for the Ossy platform — sign-in, sign-up, session verification, and invitation flows. Pages are auto-discovered by @ossy/app when the package is installed.
Pages
| File | Page id | Default paths |
|---|---|---|
| sign-in.page.jsx | sign-in | /sign-in (en), /logga-in (sv) |
| sign-up.page.jsx | sign-up | /sign-up (en), /registrera (sv) |
| verify-sign-in.page.jsx | verify-sign-in | /verify-sign-in (en), /verifiera-inloggning (sv) |
| verify-invitation.page.jsx | invitations/verify | /invitations/verify (en), /inbjudan/verifiera (sv) |
Auth pages use AuthPageLayout — a centered card inside the app shell <main> (not a full-viewport overlay).
Actions
| Action id | Access | Description |
|---|---|---|
| @ossy/authentication/actions/request-sign-in | public | Send a magic-link email for sign-in |
| @ossy/authentication/actions/verify-sign-in | public | Complete sign-in with a verification token |
| @ossy/authentication/actions/sign-up | public | Create a new user account |
| @ossy/authentication/actions/sign-out | public | End the current session and revoke the WebAuth session token (jti) when present |
| @ossy/authentication/actions/get-current-user | public | Return the authenticated user, or null |
| @ossy/authentication/actions/open-sign-in | public | Navigate to the sign-in page |
| @ossy/authentication/actions/open-sign-up | public | Navigate to the sign-up page |
Invoke via the SDK using exported action POJOs:
import { useSdk } from '@ossy/sdk-react'
import { RequestSignIn, GetCurrentUser } from '@ossy/authentication'
const sdk = useSdk()
await sdk.invoke(RequestSignIn, { email: '[email protected]' })
const user = await sdk.read(GetCurrentUser)Schemas
| Schema id | File | Purpose |
|---|---|---|
| @ossy/authentication/schema/sign-in | sign-in.schema.js | Sign-in form fields (email) |
| @ossy/authentication/schema/sign-up | sign-up.schema.js | Sign-up form fields (first name, last name, email) |
Forms reference their schema via schemaId on @ossy/authentication/form/sign-in and @ossy/authentication/form/sign-up, with validation through @ossy/schema.
Emails
| Email id | File |
|---|---|
| @ossy/authentication/emails/verify-sign-in | verify-sign-in.email.jsx |
| @ossy/authentication/emails/signed-up | signed-up.email.jsx |
Components
| Export | Description |
|---|---|
| SignIn | Magic-link sign-in card — embeddable in pages, modals, or side panels |
| SignUp | Sign-up form card |
| VerifySignIn | Token verification step |
| VerifyInvitation | Workspace invitation acceptance |
| ApiTokens | Lists API tokens with revoke; links to @profile/api-tokens/create for new tokens |
| AuthenticationGuard | Wraps children, rendering guards for unauthenticated/loading/error states |
| Invite | Form flow for inviting a user to a workspace |
| Definition | Feature metadata (id, title, icon, status, entitlementRequired: false) |
| AuthenticationStatus | Loading state constants |
Action POJOs (RequestSignIn, SignUpAction, SignUpForm, OpenSignIn, OpenSignUp, VerifySignInAction, SignOut, GetCurrentUser) are exported from the package index for typed sdk.invoke() / sdk.read().
Session tokens
WebAuth session JWTs include a jti bound to a @ossy/tokens aggregate. Sign-out (@ossy/authentication/actions/sign-out / GET /api/v0/users/sign-off) emits TokenEvents.Revoked for that jti so the JWT cannot be reused via cookie or Authorization after logout. Cookie clearing remains the HTTP adapter’s job.
API token creation lives in @ossy/profile (CreateApiToken, page @profile/api-tokens/create).
Usage
Install the package, then run your normal build — no imports or registration needed for pages.
npm install @ossy/authentication
npm run build@ossy/app discovers pages by reading the "ossy": { "src": "./src" } field in this package's package.json. Pages are merged into the manifest alongside your app's own pages.
See the Feature packages concept doc for how this works.
Logo / branding
Auth components accept an optional logo prop. By default no logo is shown — pass your app's logo element if you want one displayed above the form:
import { SignIn } from '@ossy/authentication/src/SignIn.jsx'
import { Logo } from './logo/Logo.jsx'
<SignIn logo={<Logo />} />The page entries (*.page.jsx) do not pass a logo. If you need a branded page, create a local wrapper page in your app's src/ that renders the component directly.
Peer dependencies
| Package | Version |
|---|---|
| @ossy/design-system | >=1.0.0 |
| @ossy/router-react | >=1.0.0 |
| @ossy/schema | * |
| @ossy/sdk-react | >=1.0.0 |
| @ossy/workspaces | >=1.0.0 |
| react | >=19.0.0 <20.0.0 |
