
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@strav/jina
Advanced tools
Headless authentication flows for the Strav framework. Registration, login, logout, password reset, email verification, two-factor authentication (TOTP), password confirmation, and profile updates — all as JSON API endpoints.
bun add @strav/jina
bun strav install jina
Requires @strav/core as a peer dependency.
import { defineActions } from '@strav/jina'
import User from './models/user'
const actions = defineActions<User>({
async createUser(data) { return User.create(data) },
async findByEmail(email) { return User.query().where('email', email).first() },
async findById(id) { return User.find(id) },
passwordHashOf(user) { return user.password },
emailOf(user) { return user.email },
async updatePassword(user, pw) { user.password = pw; await user.save() },
})
import { JinaProvider } from '@strav/jina'
app.use(new JinaProvider(actions))
Routes are registered automatically:
| Method | Path | Feature |
|---|---|---|
| POST | /register | registration |
| POST | /login | login |
| POST | /logout | logout |
| POST | /forgot-password | password-reset |
| POST | /reset-password | password-reset |
| POST | /email/send | email-verification |
| GET | /email/verify/:token | email-verification |
| POST | /two-factor/enable | two-factor |
| POST | /two-factor/confirm | two-factor |
| DELETE | /two-factor | two-factor |
| POST | /two-factor/challenge | two-factor |
| POST | /confirm-password | password-confirmation |
| PUT | /password | update-password |
| PUT | /profile | update-profile |
import { verified, confirmed, twoFactorChallenge } from '@strav/jina'
router.group({ middleware: [auth(), verified()] }, r => {
r.delete('/account', compose([confirmed()], deleteAccountHandler))
})
See the full Jina guide.
MIT
FAQs
Headless authentication flows for the Strav framework
The npm package @strav/jina receives a total of 2 weekly downloads. As such, @strav/jina popularity was classified as not popular.
We found that @strav/jina demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.