{"repo":"curityio/oauth-agent-node-express","free":true,"listed":false,"github":"https://github.com/curityio/oauth-agent-node-express","clone":"git clone https://github.com/curityio/oauth-agent-node-express.git","description":"A Node.js OAuth Agent, providing API driven OAuth and OpenID Connect for SPAs","language":"TypeScript","stars":49,"topics":["spa","token-handler","oauth2","oauth-agent","openid-connect","express"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"A Node.js OAuth Agent for SPAs Overview The OAuth Agent acts as a modern Back End for Front End (BFF) for Single Page Applications.\\ This implementation demonstrates the standard pattern for SPAs: - Strongest browser security with only SameSite=strict cookies - The OpenID Connect flow uses Authorization Code Flow (PKCE) and a client secret Architecture The following endpoints are implemented by the OAuth agent.\\ The SPA calls these endpoints via one liners, to perform its OAuth work: Endpoint Description -------- ----------- POST /oauth-agent/login/start Start a login by providing the request URL to the SPA and setting temporary cookies POST /oauth-agent/login/end Complete a login and issuing secure cookies for the SPA containing encrypted tokens GET /oauth-agent/userInfo Return information from the User Info endpoint for the SPA to display GET /oauth-agent/claims Return ID token claims such as auth time and acr POST /oauth-agent/refresh Refresh an access token and rewrite cookies POST /oauth-agent/logout Clear cookies and return an end session request URL For further details see the Architecture article. Deployment Build the OAuth agent into a Docker image: Then deploy the Docker image with environment variables similar to these: If the OAuth Agent is deployed to the web domain, then set these properties: In development setups, HTTP URLs can be used and certificate values left blank. OAuth Agent Development See the Setup article for details on productive OAuth Agent developm","default_branch":null,"files":null,"tree":[],"storefront":"/r/curityio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/curityio/oauth-agent-node-express/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}