npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@verii/base-contract-io

v1.2.1

Published

Package contains functions needed across all contract io packages

Readme

@verii/base-contract-io

VNF client OAuth creds resolution

The VNF authentication plugin decorates Fastify with resolveVnfClientOAuthCreds(request). Applications can install this decorator before registering authenticateVnfClientPlugin to select VNF OAuth creds for each request.

Register the custom decorator before authenticateVnfClientPlugin. When the decorator is installed from another Fastify plugin, wrap that plugin with fastify-plugin so the decorator is visible to the authentication plugin. Registering it later causes the authentication plugin to install its default decorator first, and the custom registration will fail because the decorator already exists.

A resolver returns OAuth client metadata and a lazy OAuth creds loader:

fastify.decorate('resolveVnfClientOAuthCreds', async (request) => ({
  cacheKey: request.tenantId,
  loadOAuthCreds: async () => ({
    clientId: await readClientId(request.tenantId),
    clientSecret: await readClientSecret(request.tenantId),
  }),
}));

cacheKey must be a non-empty, stable, non-secret string. Use the identity that owns the OAuth creds, such as a tenant or CAO DID. Do not include a client secret, a digest of a client secret, or any value derived from a client secret. Tokens are cached by both their audience and this resolver cache key, so an existing token remains usable until its normal expiry after the stored OAuth creds change.

The plugin calls the resolver once per incoming Fastify request so that an application can select the current credential version. Blockchain operations may make multiple JSON-RPC calls during that request; all of them reuse the same resolver result. A resolver rejection is likewise retained for the remainder of that request.

The plugin invokes loadOAuthCreds only when there is no live token for the resulting audience and cache key. It must resolve to non-empty string clientId and clientSecret values. This allows credential stores such as KMS to remain untouched on token-cache hits.

If an application does not install a resolver, the plugin installs a default one backed by fastify.config.vnfClientId and fastify.config.vnfClientSecret. Both values are required when the plugin starts in this mode. A custom resolver is preserved as-is: if it rejects, the authentication rejects and the plugin does not fall back to the configured credentials.

The published low-level initAuthenticateVnfClient function also continues to accept its original { audience, clientId, clientSecret } input. New applications should prefer the resolver contract.