Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
passport-anonym-uuid
Advanced tools
Anonymous authentication strategy for Passport that supply an uuid.
Passport strategy for anonymous authentication with a unique uuid for the anonymous user.
This module lets you provide anonymous authentication in your Node.js applications. By plugging into Passport, anonymous authentication can be easily and unobtrusively integrated into any application or framework that supports Connect-style middleware, including Express.
$ npm install passport-anonym-uuid
The anonymous authentication strategy passes authentication for a request,
with req.user
supplied with {uuid: "anonymous_<uuid>"}
.
passport.use(new AnonymIdStrategy());
If you pass a done
verify function to the strategy it will be supplied with req
and the generated uuid
.
With such verify callback, you can use this strategy the same way as passport-req. The strategy will not touch the user object returned by the callback.
Use passport.authenticate()
, specifying the 'anonymId'
strategy, to
pass authentication of a request. This is typically used alongside a strategy
that verifies credentials, as a fallback for routes that prefer authentication
but can also respond to unauthenticated requests.
For example, as route middleware in an Express application:
app.post('/hello',
passport.authenticate(['basic', 'anonymId'], { session: false }),
function(req, res) {
if (!req.user.uuid) {
res.json({ name: req.user.username });
} else {
res.json({ name: req.user.uuid });
}
});
For a complete, working example, refer to the login example.
$ npm install
$ npm test
This package is almost a copy of passport-anonymous made by Jared Hanson.
Copyright (c) 2017 Honoré Nintunze
FAQs
Anonymous authentication strategy for Passport that supply an uuid.
The npm package passport-anonym-uuid receives a total of 323 weekly downloads. As such, passport-anonym-uuid popularity was classified as not popular.
We found that passport-anonym-uuid demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.