haaremy-auth
v2.0.0
Published
Haaremy SSO Auth SDK v1.0.1 — apps-Claim, hasApp(), requiredApp-Guard
Maintainers
Readme
@haaremy/auth
Offizielles Auth-SDK für alle Haaremy-Apps. Kapselt Token-Handling, Login/Logout, BroadcastChannel Tab-Sync und Next.js-Integration.
Installation
npm install @haaremy/authEntrypoints
| Import | Beschreibung |
|--------|-------------|
| @haaremy/auth | Vanilla-JS Core (~2KB) — für alle Apps |
| @haaremy/auth/react | React useAuth Hook + HmyLoginForm |
| @haaremy/auth/next | Next.js Middleware + Server-Side Helpers (Edge-Runtime) |
Vanilla-JS / Astro / SvelteKit
import { init, login, logout, subscribe, getAccessToken, authFetch } from '@haaremy/auth'
// Einmalig beim App-Start initialisieren (prüft bestehenden Session-Cookie)
await init({ ssoUrl: 'https://sso.haaremy.de' })
// Auth-State abonnieren
const unsubscribe = subscribe((state, user) => {
console.log(state) // 'loading' | 'authenticated' | 'unauthenticated'
console.log(user) // HmyUser | null
})
// Einloggen
const user = await login({ username_or_email: '[email protected]', password: 'secret' })
// Authentifizierte API-Anfragen
const res = await authFetch('/api/data')
// Ausloggen
await logout()React
import { HmyAuthProvider, useAuth, HmyLoginForm } from '@haaremy/auth/react'
// App-Root
function App() {
return (
<HmyAuthProvider config={{ ssoUrl: 'https://sso.haaremy.de' }}>
<MyPage />
</HmyAuthProvider>
)
}
// In Komponenten
function MyPage() {
const { state, user, login, logout } = useAuth()
if (state === 'loading') return <div>Lade...</div>
if (state === 'unauthenticated') return <HmyLoginForm onSuccess={console.log} />
return (
<div>
<p>Hallo, {user?.display_name}!</p>
<button onClick={logout}>Abmelden</button>
</div>
)
}Next.js Middleware
// middleware.ts
import { createHmyMiddleware } from '@haaremy/auth/next'
export default createHmyMiddleware({
ssoUrl: 'https://sso.haaremy.de',
publicPaths: ['/login', '/register', '/api/public*'],
loginPath: '/login',
jwksCacheTtlSeconds: 3600, // JWKS 1h cachen
})
export const config = {
matcher: ['/((?!_next/static|_next/image|favicon).*)'],
}Features
- Zero localStorage — Access Token nur im JS-Memory
- BroadcastChannel Tab-Sync — Einmal anmelden → alle Tabs eingeloggt (mit 150ms ack-Timeout für Background-Tabs)
- Proaktiver Refresh — 60s vor Token-Ablauf automatisch erneuern
- Replay-Detection — Serverseitige Token-Family-Invalidierung bei Diebstahl
- JWKS-Cache — 1h offline JWT-Validierung in Next.js Middleware (kein SSO-Request pro Page Load)
- Ed25519 — Schnelle, sichere JWT-Signierung
Architektur
SSO: sso.haaremy.de
├── POST /api/v1/auth/login → access_token (JWT, 15 Min) + hmy_refresh_token Cookie
├── POST /api/v1/auth/refresh → neuer access_token (Cookie-Rotation)
├── POST /api/v1/auth/logout → Session revoken
├── GET /api/v1/auth/check → User-Info (Bearer Token)
└── GET /.well-known/jwks.json → JWKS (Ed25519 Public Keys)