Express-Authz is an authorization middleware for Express, it's based on Node-Casbin: https://github.com/casbin/node-casbin.
npm install casbin@2 casbin-express-authz@1 --savenpm install casbin@3 casbin-express-authz@2 --saveor you can simply use,
npm install express casbin casbin-express-authz --saveBy default casbin-authz supports HTTP Basic Authentication of the form Authentication: Basic {Base64Encoded(username:password)}
To use other HTTP Authentication like Bearer/Digest you can use a custom middleware to define the res.locals.username variable and casbin-authz will automatically pick up the value from the variable.
const{ newEnforcer }=require('casbin');constexpress=require('express');const{ authz }=require('casbin-express-authz');constapp=express();constenforcer=awaitnewEnforcer('examples/authz_model.conf','examples/authz_policy.csv');// set userinfoapp.use((req,res,next)=>{res.locals.username=getUsernameFromToken();// Your custom function for retrieving usernamenext();});// use authz middlewareapp.use(authz({newEnforcer: enforcer}));// responseapp.use((req,res,next)=>{res.status(200).json({status: 'OK'});});app.listen(3000);This package provides BasicAuthorizer, it uses HTTP Basic Authentication as the authentication method. If you want to use another authentication method like OAuth, you needs to implement Authorizer as below:
import{Enforcer,newEnforcer}from'casbin';import{authz,Authorizer}from'casbin-express-authz';import*asexpressfrom'express';constapp=express();classMyAuthorizerimplementsAuthorizer{privatee: Enforcer;constructor(e: Enforcer){this.e=e;}checkPermission(): Promise<boolean>{// do somethingreturntrue;}}conste=awaitnewEnforcer('examples/authz_model.conf','examples/authz_policy.csv');app.use(authz({newEnforcer: e,authorizer: newMyAuthorizer(e),}));app.listen(3000);When the authorizer needs the request and response object to check the permission, one can pass the constructor of the customized Authorizer class instead of an instance.
import{Enforcer,newEnforcer}from'casbin';import{authz,AuthorizerConstructor}from'casbin-express-authz';import{Request,Response}from'express';constapp=express();classMyAuthorizerimplementsAuthorizer{privatee: Enforcer;privatereq: Request;privateres: Respons;constructor(req:Request,res:Respons,e: Enforcer){this.e=e;this.req=reqthis.res=res}checkPermission(): Promise<boolean>{// do somethingreturntrue;}}conste=awaitnewEnforcer('examples/authz_model.conf','examples/authz_policy.csv');app.use(authz({newEnforcer: e,authorizer: MyAuthorizer,}));app.listen(3000);The authorization determines a request based on {subject, object, action}, which means what subject can perform what action on what object. In this plugin, the meanings are:
subject: the logged-on user nameobject: the URL path for the web resource like "dataset1/item1"action: HTTP method like GET, POST, PUT, DELETE, or the high-level actions you defined like "read-file", "write-blog"
For how to write authorization policy and other details, please refer to the Casbin's documentation.
This project is licensed under the Apache 2.0 license.