Skip to content

Repository files navigation

basic-auth

NPM VersionNPM DownloadsNode.js VersionBuild StatusCoverage Status

Generic basic auth Authorization header field parser for whatever.

Installation

This is a Node.js module available through the npm registry. Installation is done using the npm install command:

$ npm install basic-auth

API

const{ parse }=require('basic-auth');

parse(string)

Parse a basic auth authorization header string. This will return an object with name and pass properties, or undefined if the string is invalid.

format(credentials)

Format a credentials object with name and pass properties as a basic auth authorization header string.

Example

Pass a Basic auth header to the parse() method. If parsing fails undefined is returned, otherwise an object with .name and .pass.

const{ parse }=require('basic-auth');constuser=parse(req.headers.authorization);// => { name: 'something', pass: 'whatever' }

A header string from any other location can also be parsed for example a Proxy-Authorization header:

const{ parse }=require('basic-auth');constuser=parse(req.getHeader('Proxy-Authorization'));

A credentials object can be formatted with auth.format as basic auth header string.

const{ format }=require('basic-auth');constcredentials={name: 'foo',pass: 'bar'};constauthHeader=format(credentials);// => "Basic Zm9vOmJhcg=="

With vanilla node.js http server

consthttp=require('node:http');const{ parse }=require('basic-auth');constcompare=require('tsscmp');// Create serverconstserver=http.createServer(function(req,res){constcredentials=parse(req.headers.authorization);// Check credentials// The "check" function will typically be against your user storeif(!credentials||!check(credentials.name,credentials.pass)){res.statusCode=401;res.setHeader('WWW-Authenticate','Basic realm="example"');res.end('Access denied');}else{res.end('Access granted');}});// Basic function to validate credentials for examplefunctioncheck(name,pass){letvalid=true;// Simple method to prevent short-circuit and use timing-safe comparevalid=compare(name,'john')&&valid;valid=compare(pass,'secret')&&valid;returnvalid;}// Listenserver.listen(3000);

License

MIT

About

Generic basic auth Authorization header field parser

Topics

Resources

Code of conduct

Security policy

Stars

714 stars

Watchers

17 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages