{"repo":"samplics/modern-passport-steam","free":true,"listed":false,"github":"https://github.com/samplics/modern-passport-steam","clone":"git clone https://github.com/samplics/modern-passport-steam.git","description":"A modern passport strategy for steam that addresses vulnerability and maintainability issues","language":"JavaScript","stars":12,"topics":["javascript","modern","openid","passport","passportjs","steam","vulnerability"],"license":"MIT","category":"security-tools","readme_excerpt":"Modern Steam OpenID strategy for Passport A modern Passport strategy for authenticating with Steam using OpenID 2.0. Inspired by the original passport-steam strategy, and DoctorMcKay's node-steam-signin library. There is currently a vulnerability in the original passport-steam library that allows you to authenticate as any steam account. Installation Contents - Options - Usage - Examples Options This strategy takes an options object with the following properties: - returnUrl - The URL to which Steam will redirect the user after authentication. This should be the URL of the route that calls passport.authenticate('steam') . - realm - The URL to which Steam will redirect the user after authentication. This should be the root URL of your website. - fetchSteamLevel - Whether or not to fetch the user's Steam level. Defaults to false . Requires an API key to be provided. - fetchUserProfile - Whether or not to fetch the user's profile. Defaults to true . Requires an API key to be provided. - apiKey - A Steam API key to use for fetching the user's Steam level and profile. Can be a string or a function that returns a string. Can be async if you need to fetch the key from a remote service! - If you do not explicity set fetchUserProfile to false , an error will be thrown if you do not provide an API key. - If you do not provide an API key, the first parameter passed to the verify callback will be the SteamID object. - If you provide an API key, the first parameter passed to the verify ca","default_branch":null,"files":null,"tree":[],"storefront":"/r/samplics","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/samplics/modern-passport-steam/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}