{"repo":"curityio/nginx-lua-phantom-token-plugin","free":true,"listed":false,"github":"https://github.com/curityio/nginx-lua-phantom-token-plugin","clone":"git clone https://github.com/curityio/nginx-lua-phantom-token-plugin.git","description":"An API gateway plugin to introspect opaque access tokens and forward JWT access tokens to APIs","language":"Lua","stars":18,"topics":["introspection","kong","nginx","openresty","phantom-token","api-gateway","oauth2"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"Phantom Token Plugin for NGINX LUA Systems A LUA plugin used to introspect opaque access tokens and forward JWT access tokens to APIs. The Phantom Token Pattern The Phantom Token Pattern is a privacy preserving pattern in API security.\\ It ensures that access tokens returned to internet clients are kept confidential.\\ It also externalizes introspection and caching from APIs, to keep the API security code simple. Installation Kong API Gateway If you are using luarocks, execute the following command to install the plugin: Or deploy the .lua files into Kong's plugin directory, eg /usr/local/share/lua/5.1/kong/plugins/phantom-token . OpenResty If you are using luarocks, execute the following command to install the plugin: Or deploy the access.lua file to resty/phantom-token.lua , where the resty folder is in the lua package path .\\ A typical install location for LUA files is at /usr/local/openresty/luajit/share/lua/5.1/resty . Required Configuration Directives All of the settings in this section are required: introspection endpoint Syntax : introspection endpoint string Context : location The URL to the introspection endpoint of the Curity Identity Server. client id Syntax : client id string Context : location The ID of the introspection client configured in the Curity Identity Server. client secret Syntax : client secret string Context : location The string secret of the introspection client configured in the Curity Identity Server. Optional Configuration Directives token cache ","default_branch":null,"files":null,"tree":[],"storefront":"/r/curityio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/curityio/nginx-lua-phantom-token-plugin/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}