@veltrosecurity/suite-auth
v1.3.0
Published
Veltro-owned suite authentication contracts.
Readme
@veltrosecurity/suite-auth
Veltro-owned TypeScript suite session and service-token contracts with signed-realm compatibility.
The role and service-token behavior is transferred from VectorFlow's AGPL-3.0-or-later implementation. See NOTICE for provenance.
Authority envelope v2
verifyAuthorityEnvelopeV2 verifies and consumes short-lived ES256
veltro-suite-service+jwt envelopes. The receiver must provide the exact issuer,
exact audience, active generation, that audience's public P-256 JWK ring, required
scope, and an atomic replay consumer. The replay consumer runs exactly once after
all stateless checks and must return literal true.
This package deliberately provides no v2 minting/signing API, private-key type, key generator, JWKS/network fetcher, configuration adapter, or consumer runtime wiring. Existing HS256 v1 compatibility remains separate and unchanged.
Browser request assertion verifier
verifyBrowserRequestAssertion verifies and consumes short-lived ES256
veltro-browser-request+jwt request assertions minted by Veltro identity. The
receiver supplies the exact issuer, exact audience, active generation, that
audience's public P-256 JWK ring, the request being authorized (request.method
and request.path), and an atomic replay consumer.
The verifier enforces every binding the mint records: exact typ, alg=ES256
allowlist, audience key ring and kid, signature, issuer/audience, active
generation, nbf/iat/expiry capped at 60s, fixed realm default,
grant-product consistency, and — the point of the artifact — that the signed
method and canonical path match the request being authorized, using the same
shared normalizeRequestPath contract the mint uses. An assertion minted for
GET /chad/api/alerts never authorizes POST /chad/api/rules.
One-use semantics are the receiver's: after all stateless checks, the verifier
calls the replay consumer exactly once with a frozen {issuer, audience,
generation, jti, expiresAt} tuple. The consumer must return literal true
only if it has not previously seen that tuple; a replayed jti is rejected when
the consumer returns false. The consumer must persist at least
{issuer, audience, generation, jti} until expiresAt to enforce one-use
semantics across the token's validity window.
This package deliberately provides no request-assertion minting/signing API, private-key type, key generator, JWKS/network fetcher, configuration adapter, or consumer runtime wiring.
