
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@strav/oauth2
Advanced tools
OAuth2 server for the Strav framework. Authorization Code + PKCE, Client Credentials, Refresh Token rotation, Token Revocation (RFC 7009), Token Introspection (RFC 7662), personal access tokens, and scoped API access.
bun add @strav/oauth2
bun strav install oauth2
Requires @strav/core as a peer dependency.
import { defineActions } from '@strav/oauth2'
import User from './models/user'
const actions = defineActions<User>({
async findById(id) { return User.find(id) },
identifierOf(user) { return user.email },
})
import { OAuth2Provider } from '@strav/oauth2'
app.use(new OAuth2Provider(actions))
bun strav oauth2:setup # Create tables + personal access client
bun strav oauth2:client --name "My App" --redirect "https://app.com/callback"
import { oauth, scopes } from '@strav/oauth2'
import { compose } from '@strav/core/http/middleware'
router.group({ prefix: '/api', middleware: [oauth()] }, r => {
r.get('/user', ctx => ctx.json({ user: ctx.get('user') }))
r.get('/repos', compose([scopes('repos:read')], listRepos))
r.post('/repos', compose([scopes('repos:write')], createRepo))
})
import { oauth2 } from '@strav/oauth2'
const { token } = await oauth2.createPersonalToken(user, 'CLI Tool', ['read', 'write'])
bun strav oauth2:setup # Create tables and personal access client
bun strav oauth2:client # Create a new OAuth2 client
bun strav oauth2:purge # Clean up expired tokens and codes
See the full OAuth2 guide.
MIT
FAQs
OAuth2 server implementation for the Strav framework
The npm package @strav/oauth2 receives a total of 2 weekly downloads. As such, @strav/oauth2 popularity was classified as not popular.
We found that @strav/oauth2 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.