
Security News
Deno 2.2 Improves Dependency Management and Expands Node.js Compatibility
Deno 2.2 enhances Node.js compatibility, improves dependency management, adds OpenTelemetry support, and expands linting and task automation for developers.
auth0-ember-simple-auth
Advanced tools
Auth0's lock widget, is a nice way to get a fully functional signup and login workflow into your app.
If you don't already have an account, go signup at for free: Auth0
auth0-ember-simple-auth
using ember-cli (Ember CLI >= 0.2.7)ember new hello-safe-world
cd hello-safe-world
ember install auth0-ember-simple-auth
If you want to get up and running right away, you can scaffold all the necessary routes with to play with:
ember generate scaffold-lock
There are two configuration options.
The below simple-auth config object works out the box with the scaffold
// config/environment.js
ENV['simple-auth'] = {
authenticationRoute: 'index',
routeAfterAuthentication: 'protected',
routeIfAlreadyAuthenticated: 'protected'
}
ENV['simple-lock'] = {
clientID: "auth0_client_id",
domain: "auth0_domain"
}
At this point if you ran scaffold-lock, you can fire up ember server:
ember server --port
The below steps will outline the steps to get up and running with the scaffolding:
Ember uses a content security policy to manage which resources are allowed to be run on your pages.
// config/environment.js
ENV['contentSecurityPolicy'] = {
'font-src': "'self' data: https://*.auth0.com",
'style-src': "'self' 'unsafe-inline'",
'script-src': "'self' 'unsafe-eval' https://*.auth0.com",
'img-src': '*.gravatar.com *.wp.com data:',
'connect-src': "'self' http://localhost:* https://your-app-domain.auth0.com"
};
auth0-ember-simple-auth is just a regular authorizer that conforms to the Ember Simple Auth interface. Please follow the docs to get everything working as usual, and just add the call to the simple-auth-authenticator:lock authorizer in your authenticate
call.
Once the standard Ember Simple Auth application_route_mixin
is added to your app route, you will be able to use all the usual actions: Docs
Here is an example application route:
// app/routes/application.js
import Ember from 'ember';
import ApplicationRouteMixin from 'simple-auth/mixins/application-route-mixin';
export default Ember.Route.extend(ApplicationRouteMixin, {
actions: {
sessionRequiresAuthentication: function(){
// Check out the docs for all the options:
// https://auth0.com/docs/libraries/lock/customization
// These options will request a refresh token and launch lock.js in popup mode by default
var lockOptions = {authParams:{scope: 'openid'}};
this.get('session').authenticate('simple-auth-authenticator:lock', lockOptions);
}
}
});
Then from your template you could trigger the usual actions:
// app/templates/application.hbs
{{#if session.isAuthenticated}}
<a {{ action 'invalidateSession' }}>Logout</a>
{{else}}
<a {{ action 'sessionRequiresAuthentication' }}>Login</a>
{{/if}}
You can easily extend the Simple Lock base authenticator to play hooky with some cool hooks.
Here's how:
ember generate authenticator my-dope-authenticator
This will create the following stub authenticator:
// app/authenticators/my-dope-authenticator.js
import Base from 'simple-lock/authenticators/lock';
export default Base.extend({
/**
* Hook that gets called after the jwt has expired
* but before we notify the rest of the system.
* Great place to add cleanup to expire any third-party
* tokens or other cleanup.
*
* IMPORTANT: You must return a promise, else logout
* will not continue.
*
* @return {Promise}
*/
beforeExpire: function(){
return Ember.RSVP.resolve();
},
/**
* Hook that gets called after Auth0 successfully
* authenticates the user.
* Great place to make additional calls to other
* services, custom db, firebase, etc. then
* decorate the session object and pass it along.
*
* IMPORTANT: You must return a promise with the
* session data.
*
* @param {Object} data Session object
* @return {Promise} Promise with decorated session object
*/
afterAuth: function(data){
return Ember.RSVP.resolve(data);
},
/**
* Hook called after auth0 refreshes the jwt
* based on the refreshToken.
*
* This only fires if lock.js was passed in
* the offline_mode scope params
*
* IMPORTANT: You must return a promise with the
* session data.
*
* @param {Object} data The new jwt
* @return {Promise} The decorated session object
*/
afterRestore: function(data){
return Ember.RSVP.resolve(data);
},
/**
* Hook that gets called after Auth0 successfully
* refreshes the jwt if (refresh token is enabled).
*
* Great place to make additional calls to other
* services, custom db, firebase, etc. then
* decorate the session object and pass it along.
*
* IMPORTANT: You must return a promise with the
* session data.
*
* @param {Object} data Session object
* @return {Promise} Promise with decorated session object
*/
afterRefresh: function(data){
return Ember.RSVP.resolve(data);
}
});
Once you've made your custom authenticator. Just do the following in your app route:
import Ember from 'ember';
import ApplicationRouteMixin from 'simple-auth/mixins/application-route-mixin';
export default Ember.Route.extend(ApplicationRouteMixin, {
actions: {
sessionRequiresAuthentication: function(){
// Check out the docs for all the options:
// https://auth0.com/docs/libraries/lock/customization
var lockOptions = {authParams:{scope: 'openid'}};
this.get('session').authenticate('simple-auth-authenticator:my-dope-authenticator', lockOptions);
}
}
});
Written by @brancusi (Aram Zadikian), maintained in part by Auth0. Thanks Aram!
auth0-ember-simple-auth by Aram Zadikian. It is released under the MIT License.
Enjoy!
FAQs
Ember-simple-auth addon for Auth0 + Lock.js
We found that auth0-ember-simple-auth demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Deno 2.2 enhances Node.js compatibility, improves dependency management, adds OpenTelemetry support, and expands linting and task automation for developers.
Security News
React's CRA deprecation announcement sparked community criticism over framework recommendations, leading to quick updates acknowledging build tools like Vite as valid alternatives.
Security News
Ransomware payment rates hit an all-time low in 2024 as law enforcement crackdowns, stronger defenses, and shifting policies make attacks riskier and less profitable.