Ghost/ghost/mw-session-from-token
2021-02-17 17:09:45 +00:00
..
lib
test Remove trailing commas from .eslintrc.js files 2020-08-04 14:48:07 +01:00
types Updated type definition files 2020-05-18 15:21:44 +02:00
.eslintignore
.eslintrc.js Remove trailing commas from .eslintrc.js files 2020-08-04 14:48:07 +01:00
index.js
LICENSE 2021 2021-01-25 16:20:43 +00:00
package.json Update dependency @types/mocha to v8.2.1 2021-02-17 17:09:45 +00:00
README.md 2021 2021-01-25 16:20:43 +00:00
tsconfig.json

Session From Token Middleware

Middleware to handle generating sessions from tokens, for example like with magic links, or SSO flows similar to SAML.

Install

npm install @tryghost/mw-session-from-token --save

or

yarn add @tryghost/mw-session-from-token

Usage

const sessionFromTokenMiddleware = require('@tryghost/mw-session-from-token')({
    callNextWithError: true,
    async createSession(req, res, user) {
        req.session.user_id = user.id;
    },
    async getTokenFromRequest(res) {
        return req.headers['some-cool-header'];
    },
    async getLookupFromToken(token) {
        await someTokenService.validate(token);
        const data = await someTokenService.getData(token);
        return data.email;
    },
    async findUserByLookup(lookup) {
        return await someUserModel.findOne({email: lookup});
    }
});

someExpressApp.get('/some/sso/url', someSessionMiddleware, sessionFromTokenMiddleware, (req, res, next) => {
    res.redirect('/loggedin');
}, (err, res, res, next) => {
    res.redirect('/error');
});

Develop

This is a mono repository, managed with lerna.

Follow the instructions for the top-level repo.

  1. git clone this repo & cd into it as usual
  2. Run yarn to install top-level dependencies.

Run

  • yarn dev

Test

  • yarn lint run just eslint
  • yarn test run lint and tests

Copyright & License

Copyright (c) 2013-2021 Ghost Foundation - Released under the MIT license.