
Security News
Package Maintainers Call for Improvements to GitHub’s New npm Security Plan
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
passport-sirena-oauth2
Advanced tools
Passport strategy for authenticating with Sirena using the OAuth 2.0 API.
This module lets you authenticate using Sirena Accounts in your Node.js applications. By plugging into Passport, Sirena authentication can be easily and unobtrusively integrated into any application or framework that supports Connect-style middleware, including Express.
$ npm install passport-sirena-oauth2 --save
The Sirena authentication strategy authenticates users using the Sirena account
and OAuth 2.0 tokens. The client ID and secret obtained given by Sirena creating an
application are supplied as options when creating the strategy. The strategy
also requires a verify
callback, which receives the access token and optional
refresh token, as well as profile
which contains the authenticated user's
Sirena profile. The verify
callback must call cb
providing a user to
complete authentication.
var SirenaStrategy = require('passport-sirena-oauth2').Strategy;
passport.use(new SirenaStrategy({
authorizationURL: https://accounts.***.com/oauth2/authorize
tokenURL: https://accounts.***.com/oauth2/token
clientID: 'dashboard',
clientSecret: 'shhh-its-a-secret'
callbackURL: 'https://www.appname.net/auth/sirena/callback'
userProfileURL: 'https://www.appname.net/oauth2/profile',
scope: 'dashboardManagement' // Single scope
// scope: ['dashboardManagement', 'emailAccount'] // Multiple scopes
},
function(accessToken, refreshToken, profile, cb) {
User.findOrCreate(..., function (err, user) {
cb(err, user);
});
}
));
authorizationURL
: URL where the app needs to be authorizedclientID
: your application's client idclientSecret
: your application's client secretcallbackURL
: URL to which the Authorization Server will redirect the user after granting authorizationtokenURL
: URL where the Authorization Server will return the tokensuserProfileURL
: URL where the strategy can get the profile infoscope
: When requesting access using OAuth 2.0, the scope of access is controlled by this parameter. For one scope, just pass a string. Multiple scopes can be specified as an array.Use passport.authenticate()
, specifying the 'sirena'
strategy, to
authenticate requests.
For example, as route middleware:
app.get('/auth/sirena',
passport.authenticate('sirena', { scope: ['profile'] }));
app.get('/auth/sirena/callback',
passport.authenticate('sirena', { failureRedirect: '/login' }),
function(req, res) {
// Successful authentication, redirect home.
res.redirect('/');
});
FAQs
Sirena (OAuth 2.0) authentication strategy for Passport
We found that passport-sirena-oauth2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.