Generic basic auth Authorization header field parser for whatever.
This is a Node.js module available through the
npm registry. Installation is done using the
npm install command:
$ npm install basic-auth
const{ parse }=require('basic-auth');Parse a basic auth authorization header string. This will return an object
with name and pass properties, or undefined if the string is invalid.
Format a credentials object with name and pass properties as a basic
auth authorization header string.
Pass a Basic auth header to the parse() method. If parsing fails
undefined is returned, otherwise an object with .name and .pass.
const{ parse }=require('basic-auth');constuser=parse(req.headers.authorization);// => { name: 'something', pass: 'whatever' }A header string from any other location can also be parsed for example a Proxy-Authorization header:
const{ parse }=require('basic-auth');constuser=parse(req.getHeader('Proxy-Authorization'));A credentials object can be formatted with auth.format as
basic auth header string.
const{ format }=require('basic-auth');constcredentials={name: 'foo',pass: 'bar'};constauthHeader=format(credentials);// => "Basic Zm9vOmJhcg=="consthttp=require('node:http');const{ parse }=require('basic-auth');constcompare=require('tsscmp');// Create serverconstserver=http.createServer(function(req,res){constcredentials=parse(req.headers.authorization);// Check credentials// The "check" function will typically be against your user storeif(!credentials||!check(credentials.name,credentials.pass)){res.statusCode=401;res.setHeader('WWW-Authenticate','Basic realm="example"');res.end('Access denied');}else{res.end('Access granted');}});// Basic function to validate credentials for examplefunctioncheck(name,pass){letvalid=true;// Simple method to prevent short-circuit and use timing-safe comparevalid=compare(name,'john')&&valid;valid=compare(pass,'secret')&&valid;returnvalid;}// Listenserver.listen(3000);