@ysolve/ocity-auth-client
v0.2.0
Published
Verifies the access tokens issued by ocity_auth and protects Express routes by role and scope
Maintainers
Readme
@ysolve/ocity-auth-client
Verifies the access tokens issued by ocity_auth and protects Express routes by role and scope.
No shared secret: it only needs the public URL of the signing keys.
import { createAuthClient } from '@ysolve/ocity-auth-client'
const auth = createAuthClient({
jwksUrl: 'https://auth.o-city.org/.well-known/jwks.json',
issuer: 'https://auth.o-city.org',
audience: 'ocity',
// legacySecret: process.env.SECRET, // only while migrating from HS256; remove afterwards
})
app.get('/stories', auth.optionalAuthenticate(), listStories)
app.post('/stories', auth.authenticate(), auth.requireScope('story:write'), createStory)
app.delete('/stories/:id', auth.authenticate(), auth.requireRole(1, 2), removeStory)
// req.auth = { userId, subject, roles, scopes, tokenId }- Accepts RS256 only (HS256 just with
legacySecret). Rejectsalg: none, other algorithms and algorithm confusion. - Checks signature,
iss,audand expiry (5 s clock tolerance). - Downloads the keys once, reloads them once (every 30 s at most) for an unknown key id, and keeps using the ones it has if auth is down.
- Fails closed: without any key it answers 503, never lets a request through.
verifyToken(token)for code outside Express; throwsInvalidTokenError(401) orAuthUnavailableError(503).
Full documentation, roles, scopes and the migration plan: ocity_auth/docs/ (integration-guide.md, runbook.md).
