What is http-auth?
The http-auth npm package provides basic and digest access authentication for Node.js applications. It allows developers to secure their web applications by requiring users to provide a username and password before accessing certain routes or resources.
What are http-auth's main functionalities?
Basic Authentication
This feature allows you to set up basic authentication for your Node.js server. Users will need to provide a username and password to access the protected routes.
const http = require('http');
const auth = require('http-auth');
const basic = auth.basic({
realm: 'Simon Area',
file: __dirname + '/users.htpasswd' // user:password in htpasswd format
});
http.createServer(basic, (req, res) => {
res.end(`Welcome to private area - ${req.user}!`);
}).listen(1337, () => {
console.log('Server running at http://127.0.0.1:1337/');
});
Digest Authentication
This feature allows you to set up digest authentication for your Node.js server. Digest authentication is more secure than basic authentication as it uses MD5 hashing.
const http = require('http');
const auth = require('http-auth');
const digest = auth.digest({
realm: 'Simon Area',
file: __dirname + '/users.htdigest' // user:realm:password in htdigest format
});
http.createServer(digest, (req, res) => {
res.end(`Welcome to private area - ${req.user}!`);
}).listen(1337, () => {
console.log('Server running at http://127.0.0.1:1337/');
});
Other packages similar to http-auth
express-basic-auth
The express-basic-auth package provides basic authentication middleware for Express applications. It is simpler to use with Express compared to http-auth and integrates seamlessly with the Express framework.
passport-http
The passport-http package is a Passport strategy for HTTP Basic and Digest authentication. It is part of the Passport.js ecosystem, which provides a wide range of authentication strategies and is highly extensible.
basic-auth
The basic-auth package is a simple tool for parsing basic authentication headers. It does not provide full authentication middleware but can be used in conjunction with other packages to implement basic authentication.
http-auth
Node.js module for HTTP basic and digest access authentication.
Installation
Via git (or downloaded tarball):
$ git clone git://github.com/gevorg/http-auth.git
Via npm:
$ npm install http-auth
Digest access authentication usage
/**
* Requesting new digest access authentication instance.
*/
var digest = auth.digest({
authRealm : 'Private area with digest access authentication.',
authList : ['Shi:many222', 'Lota:123456'],
algorithm : 'MD5-sess' //Optional, default is MD5.
});
/**
* Creating new HTTP server.
*/
http.createServer(function(req, res) {
// Apply authentication to server.
digest.apply(req, res, function() {
res.end('Welcome to private area with digest access authentication!');
});
}).listen(1337);
Basic access authentication usage
/**
* Requesting new basic access authentication instance.
*/
var basic = auth.basic({
authRealm : 'Private area with basic access authentication.',
authList : ['mia:supergirl', 'Carlos:test456', 'Sam:oho']
});
/**
* Creating new HTTP server.
*/
http.createServer(function(req, res) {
// Apply authentication to server.
basic.apply(req, res, function() {
res.end('Welcome to private area with basic access authentication!');
});
}).listen(1337);
You can load users from file
/**
* Requesting new digest access authentication instance.
*/
var digest = auth.digest({
authRealm : 'Private area with digest access authentication.',
authFile : __dirname + "/users.htpasswd"
});
/**
* Creating new HTTP server.
*/
http.createServer(function(req, res) {
// Apply authentication to server.
digest.apply(req, res, function() {
res.end('Welcome to private area with digest access authentication!');
});
}).listen(1337);
/**
* Requesting new digest access authentication instance.
*/
var digest = auth.digest({
authRealm : 'Private area with digest access authentication.',
authList : ['Shi:many222', 'Lota:123456'],
algorithm : 'MD5-sess' //Optional, default is MD5.
});
/**
* Handler for digest path, with digest access authentication.
*/
app.get('/', digest.apply, function(req, res) {
res.send('Welcome to private area with digest access authentication!');
});
Configurations
- authRealm - Authentication realm.
- authFile - File where user details are stored in format {user:pass}.
- authList - List where user details are stored in format {user:pass}, ignored if authFile is specified.
- algorithm - Algorithm that will be used for authentication, may be MD5 or MD5-sess, optional, default is MD5. ONLY FOR DIGEST!
Dependencies
- node-uuid - Generate RFC4122(v4) UUIDs, and also non-RFC compact ids.
License
(The MIT License)
Copyright (c) 2011 Gevorg Harutyunyan i@gevorg.me
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the 'Software'), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.