
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@galaxy-stack/orbit-auth
Advanced tools
Module xác thực cho Orbit với JWT support sử dụng thư viện jose và password hashing với Bun native API.
import { JwtService } from '@galaxy-stack/orbit-auth';
const jwt = new JwtService({
secret: 'your-secret-key',
expiresIn: '1h',
});
// Tạo token
const token = await jwt.sign({ userId: 1, role: 'admin' });
// Verify token
const payload = await jwt.verify(token);
// Decode (không verify)
const decoded = jwt.decode(token);
import { PasswordService } from '@galaxy-stack/orbit-auth';
const password = new PasswordService();
// Hash password (sử dụng Bun.password)
const hash = await password.hash('my-password');
// Verify password
const isValid = await password.verify('my-password', hash);
import { AuthGuard, UseGuards } from '@galaxy-stack/orbit-auth';
@Controller('protected')
@UseGuards(AuthGuard)
class ProtectedController {
@Get()
getProtectedData() {
return { secret: 'data' };
}
}
import { AuthModule } from '@galaxy-stack/orbit-auth';
@Module({
imports: [
AuthModule.forRoot({
jwt: {
secret: process.env.JWT_SECRET,
expiresIn: '7d',
},
password: {
algorithm: 'argon2id', // hoặc 'bcrypt'
},
}),
],
})
class AppModule {}
AuthModule.forRootAsync({
inject: [ConfigService],
useFactory: (config: ConfigService) => ({
jwt: {
secret: config.get('JWT_SECRET'),
expiresIn: config.get('JWT_EXPIRES_IN'),
},
}),
})
interface JwtOptions {
secret: string; // Secret key
publicKey?: string; // Public key (RS256)
privateKey?: string; // Private key (RS256)
algorithm?: string; // HS256, RS256, ES256, etc.
expiresIn?: string; // '1h', '7d', '30m'
issuer?: string; // Token issuer
audience?: string; // Token audience
}
argon2id (recommended)argon2iargon2dbcryptimport { AuthGuard as BaseAuthGuard, JwtService } from '@galaxy-stack/orbit-auth';
class CustomAuthGuard extends BaseAuthGuard {
async canActivate(context: ExecutionContext): Promise<boolean> {
const request = context.switchToHttp().getRequest();
const token = this.extractToken(request);
if (!token) return false;
try {
const payload = await this.jwtService.verify(token);
request.user = payload;
return true;
} catch {
return false;
}
}
}
FAQs
Authentication module for Orbit framework
The npm package @galaxy-stack/orbit-auth receives a total of 272 weekly downloads. As such, @galaxy-stack/orbit-auth popularity was classified as not popular.
We found that @galaxy-stack/orbit-auth demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.