tekir
All Packages
Securityv0.1.10

@tekir/auth

Guard-based authentication with JWT, session, database tokens, and basic auth.

Installation

$bun add @tekir/auth

Features

  • Multiple guards: Session, JWT, DatabaseToken, AccessToken, BasicAuth
  • authenticate(), silentAuth(), and guest() middleware
  • ctx.auth with login(), logout(), generate()
  • Token listing and revocation for database tokens
  • AuthProvider for service container integration

Quick Example

TypeScript
import { authenticate } from '@tekir/auth'

app.router.get('/profile', [authenticate('jwt')], (ctx) => {
  return ctx.response.json({ user: ctx.auth.user })
})

// Login and generate token
await ctx.auth.login(user)
const token = await ctx.auth.generate()

Changelog

v0.1.10LatestSeptember 16, 2026
  • Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.9July 23, 2026
  • Package metadata now follows the shared compatible 0.1.x dependency range used by this coordinated Tekir release.
v0.1.8July 16, 2026
  • Database-token authentication now persists and verifies APP_KEY-keyed HMACs consistently, updates token usage safely, and keeps authentication middleware failures explicit.
v0.1.7June 13, 2026
  • JWT verification now enforces the algorithm. The header is decoded before the signature check and alg must be HS256 (and typ, if present, must be JWT), so alg:none and HS/RS confusion attacks are rejected. Tokens must also carry a finite exp and a sub, and nbf is honored when present.
  • Database token guard now requires APP_KEY and stores keyed-HMAC tokens. Tokens are persisted as HMAC-SHA256(token, APP_KEY) instead of a plain SHA-256 hash, the plaintext token is returned to the client only once and never written to the database, and a database leak can no longer be used to forge or replay tokens without APP_KEY. Existing stored tokens are invalidated and must be reissued.
  • Database token comparison now finishes in constant time, and an expired or unparseable expires_at is rejected rather than treated as a token that never expires.
  • Failed multi-guard authentication now returns a constant Unauthorized to the client; the guard-specific reason is only logged, so the response no longer reveals which guard failed.
  • Found and fixed with Fable.
v0.1.6May 17, 2026
  • JwtGuard.generate(user, { claims }) now throws when claims carries any of the registered names sub, iat, or exp instead of silently letting the caller override the subject or token timestamps. Reserved-claim handling is explicit, so a typo in a custom claim cannot mint a token whose sub does not match the user passed in. Apps that legitimately want a custom sub should switch to a different identity model rather than rewriting the claim.
v0.1.5May 8, 2026
  • Internal release covered by 0.1.6 notes.
v0.1.4April 29, 2026
  • Apps that augment TekirAuthUser with their own model shape (for example extends ModelFields<User>) no longer trip on a base id type conflict. The augmentation hook is now field-free so any user model fits.
v0.1.3April 27, 2026
  • AuthProvider now wires up a lightweight ctx.auth initializer onto the router automatically. Apps no longer have to add a global middleware in start/kernel.ts for handlers like /register to call auth.login(...).
  • auth.login() and auth.logout() mutate ctx.auth in place instead of replacing the object, so destructured handlers like ({ auth }) => { await auth.login(user); auth.generate() } keep working after a login swap.
  • New attachAuth() middleware exported for apps that prefer wiring it manually instead of relying on the provider.
v0.1.2April 27, 2026
  • Guard configs accept a model shortcut (any class with a static find(id)) and skip the resolver boilerplate. The shipped templates now pass model: User directly.
  • findUser config field renamed to resolve to reflect that the resolver works for any auth subject, not just users (members, accounts, admins, …).
  • New AuthModel type exported for typing custom resolver shortcuts.

Other Security packages