@serafort/svelte
v0.1.0
Published
Svelte 5 runes, stores, actions, and SvelteKit server hooks for Serafort IAM.
Readme
@serafort/svelte
Enterprise IAM & B2B Authentication adapter for Svelte and SvelteKit applications.
Features
- ⚡ Svelte Reactive Stores:
createSerafortStorewith reactiveuser,token,isAuthenticated,tenantId,roles, andpermissionsstores. - 🛠️ SvelteKit Server Hooks:
createSerafortHandleparses cookies andAuthorizationheaders, exposingevent.locals.serafort. - 🛡️ Load & Page Protection:
requireAuth(event, { permissions: ['org:*'] })with automatic 302 redirects or 401/403 errors. - 🎯 Svelte Actions:
use:permission={{ permission: 'org:*', store }}for declarative DOM visibility control. - 🏢 Multi-Tenant Isolation: Built-in verification for tenant boundaries and wildcard permissions.
Installation
npm install @serafort/svelte @serafort/coreQuick Start
1. SvelteKit Server Hook
// src/hooks.server.ts
import { createSerafortHandle } from '@serafort/svelte';
export const handle = createSerafortHandle({
endpoint: 'https://api.serafort.com',
cookieName: '__serafort_token',
});2. Protect Server Load Functions
// src/routes/dashboard/+page.server.ts
import { requireAuth } from '@serafort/svelte';
import type { PageServerLoad } from './$types';
export const load: PageServerLoad = async (event) => {
const user = requireAuth(event, {
roles: ['admin'],
permissions: ['org:*'],
});
return { user };
};3. Client Components & Actions
<!-- src/routes/+page.svelte -->
<script lang="ts">
import { createSerafortStore, permission } from '@serafort/svelte';
const serafort = createSerafortStore({
endpoint: 'https://api.serafort.com',
});
const { isAuthenticated, user, logout } = serafort;
</script>
{#if $isAuthenticated}
<h2>Hello, {$user?.userId}</h2>
<!-- Action-based permission check -->
<button use:permission={{ permission: 'org:delete', store: serafort }}>
Delete Organization
</button>
<button on:click={logout}>Sign Out</button>
{/if}Contributing
Before committing, changes are checked with pnpm run type-check.
This is wired up two ways — pick whichever fits your setup:
- Husky (npm-idiomatic, default for contributors who run
pnpm install): thepreparescript installs a Husky hook automatically, so once you've runpnpm installin a git checkout,git commitruns the checks for you. .githooks/(portable, no Husky/Node required to install): rungit config core.hooksPath .githooksonce to point git directly at the checked-in.githooks/pre-commitscript, which runs the same checks.
Both hooks run the same command, so pick one — you don't need both active at once.
CI (.github/workflows/ci.yml) runs type-check, test, and build on
every push to main and on every pull request.
