Security News
RubyGems.org Adds New Maintainer Role
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
@startupjs/auth-azuread
Advanced tools
@startupjs/auth: >= 0.33.0
react-native-webview: 10.10.2
1 - Go to Microsoft Azure portal
2 - Create an account if you don't have one
3 - Go to Active Directory
4 - Go to the tab App registration
5 - Then New registration, fill in the fields
6 - Copy Client ID as AZUREAD_CLIENT_ID
in config.json
7 - Copy Tentant ID as AZUREAD_TENTANT_ID
in config.json
8 - Go to the tab Endpoints, copy Idenitty metadata as AZUREAD_IDENTITY_METADATA
in config.json. Instead of common/organizations must stand Tentant ID.
9 - In the tab Certificates and secrets, create client secret, copy as AZUREAD_CLIENT_SECRET
in config.json.
10 - Next, you need to configure URI redirects, to do this, go to the tab with the redirect URI settings. Create platforms with links:
SPA platform - http://localhost:3000/auth/azuread/callback
Web platform - http://localhost:3000/auth/azuread/callback-native
11 - In the manifest, specify the data:
"oauth2AllowIdTokenImplicitFlow": true,
"oauth2AllowImplicitFlow": true
Importing a strategy:
import { Strategy as AzureadStrategy } from '@startupjs/auth-azuread/server'
Importing lib for the config:
import conf from 'nconf'
In startupjsServer, in the strategy of the initAuth function need to add AzureadStrategy, with variables from the config:
initAuth(ee, {
strategies: [
new AzureADStrategy({
clientId: conf.get('AZUREAD_CLIENT_ID'),
clientSecret: conf.get('AZUREAD_CLIENT_SECRET'),
tentantId: conf.get('AZUREAD_TENTANT_ID'),
identityMetadata: conf.get('AZUREAD_IDENTITY_METADATA'),
allowHttpForRedirectUrl: process.env.NODE_ENV !== 'production'
})
]
})
Parameter allowHttpForRedirectUrl
- determines whether it can be used http
for redirect url
For production, you need to use https in BASE_URL, and the condition process.env.NODE_ENV !== 'production'
import { AuthButton as AzureadAuthButton } from '@startupjs/auth-azuread/client'
FAQs
AzueAd auth plugin for StartupJS auth module
The npm package @startupjs/auth-azuread receives a total of 1 weekly downloads. As such, @startupjs/auth-azuread popularity was classified as not popular.
We found that @startupjs/auth-azuread demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.
Security News
Research
Socket's threat research team has detected five malicious npm packages targeting Roblox developers, deploying malware to steal credentials and personal data.