Repository files navigation

Auth0 Server Setup

This template is designed to help kickstart a project that utilizes Auth0. The bulk of the structure has been setup and requires a few pieces of configuration.

The first thing you will need to provide is in the .env file. You will need to supply the port, Auth0 credentials, and mongoDb connectionstring. These environment variables are used throughout the template, so be sure to add them in when moving into production as well.

.env

PORT=
CONNECTION_STRING=
AUTH_DOMAIN=
AUTH_AUDIENCE=
AUTH_CLIENT_ID=

MVC - Controllers

This template will automatically register all of the controllers found in the controllers folder of the server. This opinionated workflow should help provide a structure on how to build your api. Generally speaking every controller method should start with a try catch block and utilize the default error handler setup in Startup.js This means if a request ever fails the controller should call the next function with the error provided.

MVC - Services

Services are responsible for implementing and enforcing your business rules. Be sure to use them wisely and do not put your business logic in controllers. Services should be usable by both controllers and sockets and potentally other services. Never directly access the DbContext outside of a service.

MVC - (Models, Collections & DbContext)

Models are defined as mongoose schemas and then imported into a central location called the DbContext. All access to the database should be limited to the DbContext. Collections.js is a file purely designed to avoid the common problem of magic strings. This means when you register your models and have dependencies or relationships between one or more models you should import from Collections so you know the naming is always the same.

Working with Auth0

This library provides easily configured middleware that will validate user auth tokens, roles, permissions and provides a simple approach to get userInfo associted with a user account. Each middleware will call next with an error on any failure so be sure to setup a default error handler. Also note that we extend the express request object with

  • req.user: { UserIdentity }
  • req.userInfo: { UserInfo }

Enable RBAC or Extended Rules (required)

In your auth0 dashboard be sure to enable RBAC or add in this custom rule

//AUTH0 RULEfunction(user,context,callback){// please note auth0 will strip any non namespaced propertiesconstnamespace='https://YOURDOMAIN.auth0.com';constassignedRoles=(context.authorization||{}).roles;letidTokenClaims=context.idToken||{};idTokenClaims[`${namespace}/roles`]=assignedRoles;context.idToken=idTokenClaims;context.idToken[namespace+'/user_metadata']=user.user_metadata;context.idToken[namespace+'/app_metadata']=user.app_metadata;callback(null,user,context);}

Example of how to use and configure auth0Provider, You can configure the auth0Provider anywhere in your application and then import it and use the middleware anywhere

import{auth0Provider}from"@bcw/auth0-server";auth0Provider.configure({domain: process.env.AUTH_DOMAIN,clientId: process.env.AUTH_CLIENT_ID,audience: process.env.AUTH_AUDIENCE});// validates a request has a Bearer auth token in req.headers.authenticationapp.use("/authenticated",auth0Provider.isAuthenticated,(req,res,next)=>{res.send({userIdentity: req.user});});// validates the request token and extracts the userInfo saved in auth0app.use("/user-profile",getAuthorizedUserInfo,(req,res,next)=>{res.send({userIdentity: req.user,userInfo: req.userInfo});});// validates the request token, extracts the userIdentity and userInfo// fails if role is not found in the token// Enable RBAC or Extended Rulesapp.use("/admins-only",auth0Provider.hasRoles("admin"),(req,res,next)=>{});// validates the request token, extracts the userIdentity and userInfo// fails if any permission is not found in the token// Enable RBAC or Extended Rulesapp.use("/messages",auth0Provider.hasPermissions(["read:messages","write:messages"]),(req,res,next)=>{});//recommended default error handlerapp.use((error,req,res,next)=>{if(error.status==500||!error.status){error.message=console.error(error);// should write to external}error=error||{status: 400,message: "An unexpected error occured please try again later"};res.status(error.status).send({ ...error,url: req.url});});

Using chained methods with express.Router()

express.Router().get("",this.getAll).use(AuthorizationService.isAuthorized)// everything below this point requires authorization.get("/:id",this.getById);.put("/:id",this.updateById);.use(AuthorizationService.hasPermission("delete:blog"))// requires permission to reach this point.delete("/:id",this.deleteById);

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Auth0 Server Setup

This template is designed to help kickstart a project that utilizes Auth0. The bulk of the structure has been setup and requires a few pieces of configuration.

The first thing you will need to provide is in the .env file. You will need to supply the port, Auth0 credentials, and mongoDb connectionstring. These environment variables are used throughout the template, so be sure to add them in when moving into production as well.

.env

PORT=
CONNECTION_STRING=
AUTH_DOMAIN=
AUTH_AUDIENCE=
AUTH_CLIENT_ID=

MVC - Controllers

This template will automatically register all of the controllers found in the controllers folder of the server. This opinionated workflow should help provide a structure on how to build your api. Generally speaking every controller method should start with a try catch block and utilize the default error handler setup in Startup.js This means if a request ever fails the controller should call the next function with the error provided.

MVC - Services

Services are responsible for implementing and enforcing your business rules. Be sure to use them wisely and do not put your business logic in controllers. Services should be usable by both controllers and sockets and potentally other services. Never directly access the DbContext outside of a service.

MVC - (Models, Collections & DbContext)

Models are defined as mongoose schemas and then imported into a central location called the DbContext. All access to the database should be limited to the DbContext. Collections.js is a file purely designed to avoid the common problem of magic strings. This means when you register your models and have dependencies or relationships between one or more models you should import from Collections so you know the naming is always the same.

Working with Auth0

This library provides easily configured middleware that will validate user auth tokens, roles, permissions and provides a simple approach to get userInfo associted with a user account. Each middleware will call next with an error on any failure so be sure to setup a default error handler. Also note that we extend the express request object with

  • req.user: { UserIdentity }
  • req.userInfo: { UserInfo }

Enable RBAC or Extended Rules (required)

In your auth0 dashboard be sure to enable RBAC or add in this custom rule

//AUTH0 RULEfunction(user,context,callback){// please note auth0 will strip any non namespaced propertiesconstnamespace='https://YOURDOMAIN.auth0.com';constassignedRoles=(context.authorization||{}).roles;letidTokenClaims=context.idToken||{};idTokenClaims[`${namespace}/roles`]=assignedRoles;context.idToken=idTokenClaims;context.idToken[namespace+'/user_metadata']=user.user_metadata;context.idToken[namespace+'/app_metadata']=user.app_metadata;callback(null,user,context);}

Example of how to use and configure auth0Provider, You can configure the auth0Provider anywhere in your application and then import it and use the middleware anywhere

import{auth0Provider}from"@bcw/auth0-server";auth0Provider.configure({domain: process.env.AUTH_DOMAIN,clientId: process.env.AUTH_CLIENT_ID,audience: process.env.AUTH_AUDIENCE});// validates a request has a Bearer auth token in req.headers.authenticationapp.use("/authenticated",auth0Provider.isAuthenticated,(req,res,next)=>{res.send({userIdentity: req.user});});// validates the request token and extracts the userInfo saved in auth0app.use("/user-profile",getAuthorizedUserInfo,(req,res,next)=>{res.send({userIdentity: req.user,userInfo: req.userInfo});});// validates the request token, extracts the userIdentity and userInfo// fails if role is not found in the token// Enable RBAC or Extended Rulesapp.use("/admins-only",auth0Provider.hasRoles("admin"),(req,res,next)=>{});// validates the request token, extracts the userIdentity and userInfo// fails if any permission is not found in the token// Enable RBAC or Extended Rulesapp.use("/messages",auth0Provider.hasPermissions(["read:messages","write:messages"]),(req,res,next)=>{});//recommended default error handlerapp.use((error,req,res,next)=>{if(error.status==500||!error.status){error.message=console.error(error);// should write to external}error=error||{status: 400,message: "An unexpected error occured please try again later"};res.status(error.status).send({ ...error,url: req.url});});

Using chained methods with express.Router()

express.Router().get("",this.getAll).use(AuthorizationService.isAuthorized)// everything below this point requires authorization.get("/:id",this.getById);.put("/:id",this.updateById);.use(AuthorizationService.hasPermission("delete:blog"))// requires permission to reach this point.delete("/:id",this.deleteById);

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Auth0 Server Setup

This template is designed to help kickstart a project that utilizes Auth0. The bulk of the structure has been setup and requires a few pieces of configuration.

The first thing you will need to provide is in the .env file. You will need to supply the port, Auth0 credentials, and mongoDb connectionstring. These environment variables are used throughout the template, so be sure to add them in when moving into production as well.

.env

PORT=
CONNECTION_STRING=
AUTH_DOMAIN=
AUTH_AUDIENCE=
AUTH_CLIENT_ID=

MVC - Controllers

This template will automatically register all of the controllers found in the controllers folder of the server. This opinionated workflow should help provide a structure on how to build your api. Generally speaking every controller method should start with a try catch block and utilize the default error handler setup in Startup.js This means if a request ever fails the controller should call the next function with the error provided.

MVC - Services

Services are responsible for implementing and enforcing your business rules. Be sure to use them wisely and do not put your business logic in controllers. Services should be usable by both controllers and sockets and potentally other services. Never directly access the DbContext outside of a service.

MVC - (Models, Collections & DbContext)

Models are defined as mongoose schemas and then imported into a central location called the DbContext. All access to the database should be limited to the DbContext. Collections.js is a file purely designed to avoid the common problem of magic strings. This means when you register your models and have dependencies or relationships between one or more models you should import from Collections so you know the naming is always the same.

Working with Auth0

This library provides easily configured middleware that will validate user auth tokens, roles, permissions and provides a simple approach to get userInfo associted with a user account. Each middleware will call next with an error on any failure so be sure to setup a default error handler. Also note that we extend the express request object with

  • req.user: { UserIdentity }
  • req.userInfo: { UserInfo }

Enable RBAC or Extended Rules (required)

In your auth0 dashboard be sure to enable RBAC or add in this custom rule

//AUTH0 RULEfunction(user,context,callback){// please note auth0 will strip any non namespaced propertiesconstnamespace='https://YOURDOMAIN.auth0.com';constassignedRoles=(context.authorization||{}).roles;letidTokenClaims=context.idToken||{};idTokenClaims[`${namespace}/roles`]=assignedRoles;context.idToken=idTokenClaims;context.idToken[namespace+'/user_metadata']=user.user_metadata;context.idToken[namespace+'/app_metadata']=user.app_metadata;callback(null,user,context);}

Example of how to use and configure auth0Provider, You can configure the auth0Provider anywhere in your application and then import it and use the middleware anywhere

import{auth0Provider}from"@bcw/auth0-server";auth0Provider.configure({domain: process.env.AUTH_DOMAIN,clientId: process.env.AUTH_CLIENT_ID,audience: process.env.AUTH_AUDIENCE});// validates a request has a Bearer auth token in req.headers.authenticationapp.use("/authenticated",auth0Provider.isAuthenticated,(req,res,next)=>{res.send({userIdentity: req.user});});// validates the request token and extracts the userInfo saved in auth0app.use("/user-profile",getAuthorizedUserInfo,(req,res,next)=>{res.send({userIdentity: req.user,userInfo: req.userInfo});});// validates the request token, extracts the userIdentity and userInfo// fails if role is not found in the token// Enable RBAC or Extended Rulesapp.use("/admins-only",auth0Provider.hasRoles("admin"),(req,res,next)=>{});// validates the request token, extracts the userIdentity and userInfo// fails if any permission is not found in the token// Enable RBAC or Extended Rulesapp.use("/messages",auth0Provider.hasPermissions(["read:messages","write:messages"]),(req,res,next)=>{});//recommended default error handlerapp.use((error,req,res,next)=>{if(error.status==500||!error.status){error.message=console.error(error);// should write to external}error=error||{status: 400,message: "An unexpected error occured please try again later"};res.status(error.status).send({ ...error,url: req.url});});

Using chained methods with express.Router()

express.Router().get("",this.getAll).use(AuthorizationService.isAuthorized)// everything below this point requires authorization.get("/:id",this.getById);.put("/:id",this.updateById);.use(AuthorizationService.hasPermission("delete:blog"))// requires permission to reach this point.delete("/:id",this.deleteById);

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Auth0 Server Setup

This template is designed to help kickstart a project that utilizes Auth0. The bulk of the structure has been setup and requires a few pieces of configuration.

The first thing you will need to provide is in the .env file. You will need to supply the port, Auth0 credentials, and mongoDb connectionstring. These environment variables are used throughout the template, so be sure to add them in when moving into production as well.

.env

PORT=
CONNECTION_STRING=
AUTH_DOMAIN=
AUTH_AUDIENCE=
AUTH_CLIENT_ID=

MVC - Controllers

This template will automatically register all of the controllers found in the controllers folder of the server. This opinionated workflow should help provide a structure on how to build your api. Generally speaking every controller method should start with a try catch block and utilize the default error handler setup in Startup.js This means if a request ever fails the controller should call the next function with the error provided.

MVC - Services

Services are responsible for implementing and enforcing your business rules. Be sure to use them wisely and do not put your business logic in controllers. Services should be usable by both controllers and sockets and potentally other services. Never directly access the DbContext outside of a service.

MVC - (Models, Collections & DbContext)

Models are defined as mongoose schemas and then imported into a central location called the DbContext. All access to the database should be limited to the DbContext. Collections.js is a file purely designed to avoid the common problem of magic strings. This means when you register your models and have dependencies or relationships between one or more models you should import from Collections so you know the naming is always the same.

Working with Auth0

This library provides easily configured middleware that will validate user auth tokens, roles, permissions and provides a simple approach to get userInfo associted with a user account. Each middleware will call next with an error on any failure so be sure to setup a default error handler. Also note that we extend the express request object with

  • req.user: { UserIdentity }
  • req.userInfo: { UserInfo }

Enable RBAC or Extended Rules (required)

In your auth0 dashboard be sure to enable RBAC or add in this custom rule

//AUTH0 RULEfunction(user,context,callback){// please note auth0 will strip any non namespaced propertiesconstnamespace='https://YOURDOMAIN.auth0.com';constassignedRoles=(context.authorization||{}).roles;letidTokenClaims=context.idToken||{};idTokenClaims[`${namespace}/roles`]=assignedRoles;context.idToken=idTokenClaims;context.idToken[namespace+'/user_metadata']=user.user_metadata;context.idToken[namespace+'/app_metadata']=user.app_metadata;callback(null,user,context);}

Example of how to use and configure auth0Provider, You can configure the auth0Provider anywhere in your application and then import it and use the middleware anywhere

import{auth0Provider}from"@bcw/auth0-server";auth0Provider.configure({domain: process.env.AUTH_DOMAIN,clientId: process.env.AUTH_CLIENT_ID,audience: process.env.AUTH_AUDIENCE});// validates a request has a Bearer auth token in req.headers.authenticationapp.use("/authenticated",auth0Provider.isAuthenticated,(req,res,next)=>{res.send({userIdentity: req.user});});// validates the request token and extracts the userInfo saved in auth0app.use("/user-profile",getAuthorizedUserInfo,(req,res,next)=>{res.send({userIdentity: req.user,userInfo: req.userInfo});});// validates the request token, extracts the userIdentity and userInfo// fails if role is not found in the token// Enable RBAC or Extended Rulesapp.use("/admins-only",auth0Provider.hasRoles("admin"),(req,res,next)=>{});// validates the request token, extracts the userIdentity and userInfo// fails if any permission is not found in the token// Enable RBAC or Extended Rulesapp.use("/messages",auth0Provider.hasPermissions(["read:messages","write:messages"]),(req,res,next)=>{});//recommended default error handlerapp.use((error,req,res,next)=>{if(error.status==500||!error.status){error.message=console.error(error);// should write to external}error=error||{status: 400,message: "An unexpected error occured please try again later"};res.status(error.status).send({ ...error,url: req.url});});

Using chained methods with express.Router()

express.Router().get("",this.getAll).use(AuthorizationService.isAuthorized)// everything below this point requires authorization.get("/:id",this.getById);.put("/:id",this.updateById);.use(AuthorizationService.hasPermission("delete:blog"))// requires permission to reach this point.delete("/:id",this.deleteById);

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Auth0 Server Setup

This template is designed to help kickstart a project that utilizes Auth0. The bulk of the structure has been setup and requires a few pieces of configuration.

The first thing you will need to provide is in the .env file. You will need to supply the port, Auth0 credentials, and mongoDb connectionstring. These environment variables are used throughout the template, so be sure to add them in when moving into production as well.

.env

PORT=
CONNECTION_STRING=
AUTH_DOMAIN=
AUTH_AUDIENCE=
AUTH_CLIENT_ID=

MVC - Controllers

This template will automatically register all of the controllers found in the controllers folder of the server. This opinionated workflow should help provide a structure on how to build your api. Generally speaking every controller method should start with a try catch block and utilize the default error handler setup in Startup.js This means if a request ever fails the controller should call the next function with the error provided.

MVC - Services

Services are responsible for implementing and enforcing your business rules. Be sure to use them wisely and do not put your business logic in controllers. Services should be usable by both controllers and sockets and potentally other services. Never directly access the DbContext outside of a service.

MVC - (Models, Collections & DbContext)

Models are defined as mongoose schemas and then imported into a central location called the DbContext. All access to the database should be limited to the DbContext. Collections.js is a file purely designed to avoid the common problem of magic strings. This means when you register your models and have dependencies or relationships between one or more models you should import from Collections so you know the naming is always the same.

Working with Auth0

This library provides easily configured middleware that will validate user auth tokens, roles, permissions and provides a simple approach to get userInfo associted with a user account. Each middleware will call next with an error on any failure so be sure to setup a default error handler. Also note that we extend the express request object with

  • req.user: { UserIdentity }
  • req.userInfo: { UserInfo }

Enable RBAC or Extended Rules (required)

In your auth0 dashboard be sure to enable RBAC or add in this custom rule

//AUTH0 RULEfunction(user,context,callback){// please note auth0 will strip any non namespaced propertiesconstnamespace='https://YOURDOMAIN.auth0.com';constassignedRoles=(context.authorization||{}).roles;letidTokenClaims=context.idToken||{};idTokenClaims[`${namespace}/roles`]=assignedRoles;context.idToken=idTokenClaims;context.idToken[namespace+'/user_metadata']=user.user_metadata;context.idToken[namespace+'/app_metadata']=user.app_metadata;callback(null,user,context);}

Example of how to use and configure auth0Provider, You can configure the auth0Provider anywhere in your application and then import it and use the middleware anywhere

import{auth0Provider}from"@bcw/auth0-server";auth0Provider.configure({domain: process.env.AUTH_DOMAIN,clientId: process.env.AUTH_CLIENT_ID,audience: process.env.AUTH_AUDIENCE});// validates a request has a Bearer auth token in req.headers.authenticationapp.use("/authenticated",auth0Provider.isAuthenticated,(req,res,next)=>{res.send({userIdentity: req.user});});// validates the request token and extracts the userInfo saved in auth0app.use("/user-profile",getAuthorizedUserInfo,(req,res,next)=>{res.send({userIdentity: req.user,userInfo: req.userInfo});});// validates the request token, extracts the userIdentity and userInfo// fails if role is not found in the token// Enable RBAC or Extended Rulesapp.use("/admins-only",auth0Provider.hasRoles("admin"),(req,res,next)=>{});// validates the request token, extracts the userIdentity and userInfo// fails if any permission is not found in the token// Enable RBAC or Extended Rulesapp.use("/messages",auth0Provider.hasPermissions(["read:messages","write:messages"]),(req,res,next)=>{});//recommended default error handlerapp.use((error,req,res,next)=>{if(error.status==500||!error.status){error.message=console.error(error);// should write to external}error=error||{status: 400,message: "An unexpected error occured please try again later"};res.status(error.status).send({ ...error,url: req.url});});

Using chained methods with express.Router()

express.Router().get("",this.getAll).use(AuthorizationService.isAuthorized)// everything below this point requires authorization.get("/:id",this.getById);.put("/:id",this.updateById);.use(AuthorizationService.hasPermission("delete:blog"))// requires permission to reach this point.delete("/:id",this.deleteById);

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Auth0 Server Setup

This template is designed to help kickstart a project that utilizes Auth0. The bulk of the structure has been setup and requires a few pieces of configuration.

The first thing you will need to provide is in the .env file. You will need to supply the port, Auth0 credentials, and mongoDb connectionstring. These environment variables are used throughout the template, so be sure to add them in when moving into production as well.

.env

PORT=
CONNECTION_STRING=
AUTH_DOMAIN=
AUTH_AUDIENCE=
AUTH_CLIENT_ID=

MVC - Controllers

This template will automatically register all of the controllers found in the controllers folder of the server. This opinionated workflow should help provide a structure on how to build your api. Generally speaking every controller method should start with a try catch block and utilize the default error handler setup in Startup.js This means if a request ever fails the controller should call the next function with the error provided.

MVC - Services

Services are responsible for implementing and enforcing your business rules. Be sure to use them wisely and do not put your business logic in controllers. Services should be usable by both controllers and sockets and potentally other services. Never directly access the DbContext outside of a service.

MVC - (Models, Collections & DbContext)

Models are defined as mongoose schemas and then imported into a central location called the DbContext. All access to the database should be limited to the DbContext. Collections.js is a file purely designed to avoid the common problem of magic strings. This means when you register your models and have dependencies or relationships between one or more models you should import from Collections so you know the naming is always the same.

Working with Auth0

This library provides easily configured middleware that will validate user auth tokens, roles, permissions and provides a simple approach to get userInfo associted with a user account. Each middleware will call next with an error on any failure so be sure to setup a default error handler. Also note that we extend the express request object with

  • req.user: { UserIdentity }
  • req.userInfo: { UserInfo }

Enable RBAC or Extended Rules (required)

In your auth0 dashboard be sure to enable RBAC or add in this custom rule

//AUTH0 RULEfunction(user,context,callback){// please note auth0 will strip any non namespaced propertiesconstnamespace='https://YOURDOMAIN.auth0.com';constassignedRoles=(context.authorization||{}).roles;letidTokenClaims=context.idToken||{};idTokenClaims[`${namespace}/roles`]=assignedRoles;context.idToken=idTokenClaims;context.idToken[namespace+'/user_metadata']=user.user_metadata;context.idToken[namespace+'/app_metadata']=user.app_metadata;callback(null,user,context);}

Example of how to use and configure auth0Provider, You can configure the auth0Provider anywhere in your application and then import it and use the middleware anywhere

import{auth0Provider}from"@bcw/auth0-server";auth0Provider.configure({domain: process.env.AUTH_DOMAIN,clientId: process.env.AUTH_CLIENT_ID,audience: process.env.AUTH_AUDIENCE});// validates a request has a Bearer auth token in req.headers.authenticationapp.use("/authenticated",auth0Provider.isAuthenticated,(req,res,next)=>{res.send({userIdentity: req.user});});// validates the request token and extracts the userInfo saved in auth0app.use("/user-profile",getAuthorizedUserInfo,(req,res,next)=>{res.send({userIdentity: req.user,userInfo: req.userInfo});});// validates the request token, extracts the userIdentity and userInfo// fails if role is not found in the token// Enable RBAC or Extended Rulesapp.use("/admins-only",auth0Provider.hasRoles("admin"),(req,res,next)=>{});// validates the request token, extracts the userIdentity and userInfo// fails if any permission is not found in the token// Enable RBAC or Extended Rulesapp.use("/messages",auth0Provider.hasPermissions(["read:messages","write:messages"]),(req,res,next)=>{});//recommended default error handlerapp.use((error,req,res,next)=>{if(error.status==500||!error.status){error.message=console.error(error);// should write to external}error=error||{status: 400,message: "An unexpected error occured please try again later"};res.status(error.status).send({ ...error,url: req.url});});

Using chained methods with express.Router()

express.Router().get("",this.getAll).use(AuthorizationService.isAuthorized)// everything below this point requires authorization.get("/:id",this.getById);.put("/:id",this.updateById);.use(AuthorizationService.hasPermission("delete:blog"))// requires permission to reach this point.delete("/:id",this.deleteById);

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Auth0 Server Setup

This template is designed to help kickstart a project that utilizes Auth0. The bulk of the structure has been setup and requires a few pieces of configuration.

The first thing you will need to provide is in the .env file. You will need to supply the port, Auth0 credentials, and mongoDb connectionstring. These environment variables are used throughout the template, so be sure to add them in when moving into production as well.

.env

PORT=
CONNECTION_STRING=
AUTH_DOMAIN=
AUTH_AUDIENCE=
AUTH_CLIENT_ID=

MVC - Controllers

This template will automatically register all of the controllers found in the controllers folder of the server. This opinionated workflow should help provide a structure on how to build your api. Generally speaking every controller method should start with a try catch block and utilize the default error handler setup in Startup.js This means if a request ever fails the controller should call the next function with the error provided.

MVC - Services

Services are responsible for implementing and enforcing your business rules. Be sure to use them wisely and do not put your business logic in controllers. Services should be usable by both controllers and sockets and potentally other services. Never directly access the DbContext outside of a service.

MVC - (Models, Collections & DbContext)

Models are defined as mongoose schemas and then imported into a central location called the DbContext. All access to the database should be limited to the DbContext. Collections.js is a file purely designed to avoid the common problem of magic strings. This means when you register your models and have dependencies or relationships between one or more models you should import from Collections so you know the naming is always the same.

Working with Auth0

This library provides easily configured middleware that will validate user auth tokens, roles, permissions and provides a simple approach to get userInfo associted with a user account. Each middleware will call next with an error on any failure so be sure to setup a default error handler. Also note that we extend the express request object with

  • req.user: { UserIdentity }
  • req.userInfo: { UserInfo }

Enable RBAC or Extended Rules (required)

In your auth0 dashboard be sure to enable RBAC or add in this custom rule

//AUTH0 RULEfunction(user,context,callback){// please note auth0 will strip any non namespaced propertiesconstnamespace='https://YOURDOMAIN.auth0.com';constassignedRoles=(context.authorization||{}).roles;letidTokenClaims=context.idToken||{};idTokenClaims[`${namespace}/roles`]=assignedRoles;context.idToken=idTokenClaims;context.idToken[namespace+'/user_metadata']=user.user_metadata;context.idToken[namespace+'/app_metadata']=user.app_metadata;callback(null,user,context);}

Example of how to use and configure auth0Provider, You can configure the auth0Provider anywhere in your application and then import it and use the middleware anywhere

import{auth0Provider}from"@bcw/auth0-server";auth0Provider.configure({domain: process.env.AUTH_DOMAIN,clientId: process.env.AUTH_CLIENT_ID,audience: process.env.AUTH_AUDIENCE});// validates a request has a Bearer auth token in req.headers.authenticationapp.use("/authenticated",auth0Provider.isAuthenticated,(req,res,next)=>{res.send({userIdentity: req.user});});// validates the request token and extracts the userInfo saved in auth0app.use("/user-profile",getAuthorizedUserInfo,(req,res,next)=>{res.send({userIdentity: req.user,userInfo: req.userInfo});});// validates the request token, extracts the userIdentity and userInfo// fails if role is not found in the token// Enable RBAC or Extended Rulesapp.use("/admins-only",auth0Provider.hasRoles("admin"),(req,res,next)=>{});// validates the request token, extracts the userIdentity and userInfo// fails if any permission is not found in the token// Enable RBAC or Extended Rulesapp.use("/messages",auth0Provider.hasPermissions(["read:messages","write:messages"]),(req,res,next)=>{});//recommended default error handlerapp.use((error,req,res,next)=>{if(error.status==500||!error.status){error.message=console.error(error);// should write to external}error=error||{status: 400,message: "An unexpected error occured please try again later"};res.status(error.status).send({ ...error,url: req.url});});

Using chained methods with express.Router()

express.Router().get("",this.getAll).use(AuthorizationService.isAuthorized)// everything below this point requires authorization.get("/:id",this.getById);.put("/:id",this.updateById);.use(AuthorizationService.hasPermission("delete:blog"))// requires permission to reach this point.delete("/:id",this.deleteById);

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Auth0 Server Setup

This template is designed to help kickstart a project that utilizes Auth0. The bulk of the structure has been setup and requires a few pieces of configuration.

The first thing you will need to provide is in the .env file. You will need to supply the port, Auth0 credentials, and mongoDb connectionstring. These environment variables are used throughout the template, so be sure to add them in when moving into production as well.

.env

PORT=
CONNECTION_STRING=
AUTH_DOMAIN=
AUTH_AUDIENCE=
AUTH_CLIENT_ID=

MVC - Controllers

This template will automatically register all of the controllers found in the controllers folder of the server. This opinionated workflow should help provide a structure on how to build your api. Generally speaking every controller method should start with a try catch block and utilize the default error handler setup in Startup.js This means if a request ever fails the controller should call the next function with the error provided.

MVC - Services

Services are responsible for implementing and enforcing your business rules. Be sure to use them wisely and do not put your business logic in controllers. Services should be usable by both controllers and sockets and potentally other services. Never directly access the DbContext outside of a service.

MVC - (Models, Collections & DbContext)

Models are defined as mongoose schemas and then imported into a central location called the DbContext. All access to the database should be limited to the DbContext. Collections.js is a file purely designed to avoid the common problem of magic strings. This means when you register your models and have dependencies or relationships between one or more models you should import from Collections so you know the naming is always the same.

Working with Auth0

This library provides easily configured middleware that will validate user auth tokens, roles, permissions and provides a simple approach to get userInfo associted with a user account. Each middleware will call next with an error on any failure so be sure to setup a default error handler. Also note that we extend the express request object with

  • req.user: { UserIdentity }
  • req.userInfo: { UserInfo }

Enable RBAC or Extended Rules (required)

In your auth0 dashboard be sure to enable RBAC or add in this custom rule

//AUTH0 RULEfunction(user,context,callback){// please note auth0 will strip any non namespaced propertiesconstnamespace='https://YOURDOMAIN.auth0.com';constassignedRoles=(context.authorization||{}).roles;letidTokenClaims=context.idToken||{};idTokenClaims[`${namespace}/roles`]=assignedRoles;context.idToken=idTokenClaims;context.idToken[namespace+'/user_metadata']=user.user_metadata;context.idToken[namespace+'/app_metadata']=user.app_metadata;callback(null,user,context);}

Example of how to use and configure auth0Provider, You can configure the auth0Provider anywhere in your application and then import it and use the middleware anywhere

import{auth0Provider}from"@bcw/auth0-server";auth0Provider.configure({domain: process.env.AUTH_DOMAIN,clientId: process.env.AUTH_CLIENT_ID,audience: process.env.AUTH_AUDIENCE});// validates a request has a Bearer auth token in req.headers.authenticationapp.use("/authenticated",auth0Provider.isAuthenticated,(req,res,next)=>{res.send({userIdentity: req.user});});// validates the request token and extracts the userInfo saved in auth0app.use("/user-profile",getAuthorizedUserInfo,(req,res,next)=>{res.send({userIdentity: req.user,userInfo: req.userInfo});});// validates the request token, extracts the userIdentity and userInfo// fails if role is not found in the token// Enable RBAC or Extended Rulesapp.use("/admins-only",auth0Provider.hasRoles("admin"),(req,res,next)=>{});// validates the request token, extracts the userIdentity and userInfo// fails if any permission is not found in the token// Enable RBAC or Extended Rulesapp.use("/messages",auth0Provider.hasPermissions(["read:messages","write:messages"]),(req,res,next)=>{});//recommended default error handlerapp.use((error,req,res,next)=>{if(error.status==500||!error.status){error.message=console.error(error);// should write to external}error=error||{status: 400,message: "An unexpected error occured please try again later"};res.status(error.status).send({ ...error,url: req.url});});

Using chained methods with express.Router()

express.Router().get("",this.getAll).use(AuthorizationService.isAuthorized)// everything below this point requires authorization.get("/:id",this.getById);.put("/:id",this.updateById);.use(AuthorizationService.hasPermission("delete:blog"))// requires permission to reach this point.delete("/:id",this.deleteById);

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages