
Product
Announcing Socket Fix 2.0
Socket Fix 2.0 brings targeted CVE remediation, smarter upgrade planning, and broader ecosystem support to help developers get to zero alerts.
HMAC authentication module for NodeJS.
Install the module with: npm install ofuda
Ofuda = require('ofuda');
var ofuda = new Ofuda({headerPrefix:'Amz', hash: 'sha1', serviceLabel: 'AWS', accessKeyId: '44CF9590006BF252F707', accessKeySecret: 'OtxrzxIsfpFjA7SwPzILwy8Bw21TLhquhboDYROV'});
ofuda.signHttpRequest(request); // appends a hmac authorisation header to the request
(Coming soon)
Use as a client is illustrated below.
var http = require('http');
var Ofuda = require('ofuda');
var ofuda = new Ofuda({headerPrefix:'Amz', hash: 'sha1', serviceLabel: 'AWS', debug: true});
var credentials = {accessKeyId: '44CF9590006BF252F707', accessKeySecret: 'OtxrzxIsfpFjA7SwPzILwy8Bw21TLhquhboDYROV'};
http_options = {
host: 'localhost',
port: 8080,
path: '/notify',
method: 'PUT',
headers: {
'Content-Type': 'application/json',
'Content-MD5': 'ee930827ccb58cd846ca31af5faa3634'
}
};
signedOptions = ofuda.signHttpRequest(credentials, http_options);
var req = http.request(signedOptions, function(res) {
console.log('STATUS: ' + res.statusCode);
console.log('HEADERS: ' + JSON.stringify(res.headers));
});
req.write('{"some":"thing"}');
req.end();
Use as a server is as follows.
var http = require('http'),
Ofuda = require('ofuda');
var ofuda = new Ofuda({headerPrefix:'Amz', hash: 'sha1', serviceLabel: 'AWS', debug: true});
var validateCredentials = function(requestAccessKeyId){
return {accessKeyId: requestAccessKeyId, accessKeySecret: 'OtxrzxIsfpFjA7SwPzILwy8Bw21TLhquhboDYROV'};
}
http.createServer(function (request, response) {
if(ofuda.validateHttpRequest(request, validateCredentials)){
response.writeHead(200);
response.end('Success!');
} else {
response.writeHead(401)
response.end('Authorization failed!');
}
}).listen(8080);
console.log('Server running at http://127.0.0.1:8080/');
In lieu of a formal style guide, take care to maintain the existing coding style. Add unit tests for any new or changed functionality. Lint and test your code using grunt.
(Nothing yet)
Copyright (c) 2012 Mark Wolfe
Licensed under the MIT license.
FAQs
HMAC authentication for nodejs which should be compatible with Amazon.
We found that ofuda demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Product
Socket Fix 2.0 brings targeted CVE remediation, smarter upgrade planning, and broader ecosystem support to help developers get to zero alerts.
Security News
Socket CEO Feross Aboukhadijeh joins Risky Business Weekly to unpack recent npm phishing attacks, their limited impact, and the risks if attackers get smarter.
Product
Socket’s new Tier 1 Reachability filters out up to 80% of irrelevant CVEs, so security teams can focus on the vulnerabilities that matter.