Securityv0.1.10
@tekir/auth
Guard-based authentication with JWT, session, database tokens, and basic auth.
Installation
$
bun add @tekir/authFeatures
- Multiple guards: Session, JWT, DatabaseToken, AccessToken, BasicAuth
- authenticate(), silentAuth(), and guest() middleware
- ctx.auth with login(), logout(), generate()
- Token listing and revocation for database tokens
- AuthProvider for service container integration
Quick Example
TypeScript
import { authenticate } from '@tekir/auth'
app.router.get('/profile', [authenticate('jwt')], (ctx) => {
return ctx.response.json({ user: ctx.auth.user })
})
// Login and generate token
await ctx.auth.login(user)
const token = await ctx.auth.generate()Changelog
v0.1.10LatestSeptember 16, 2026
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.9July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.8July 16, 2026
- Database-token authentication now persists and verifies APP_KEY-keyed HMACs consistently, updates token usage safely, and keeps authentication middleware failures explicit.
v0.1.7June 13, 2026
- JWT verification now enforces the algorithm. The header is decoded before the signature check and
algmust beHS256(andtyp, if present, must beJWT), soalg:noneand HS/RS confusion attacks are rejected. Tokens must also carry a finiteexpand asub, andnbfis honored when present. - Database token guard now requires
APP_KEYand stores keyed-HMAC tokens. Tokens are persisted asHMAC-SHA256(token, APP_KEY)instead of a plain SHA-256 hash, the plaintext token is returned to the client only once and never written to the database, and a database leak can no longer be used to forge or replay tokens withoutAPP_KEY. Existing stored tokens are invalidated and must be reissued. - Database token comparison now finishes in constant time, and an expired or unparseable
expires_atis rejected rather than treated as a token that never expires. - Failed multi-guard authentication now returns a constant
Unauthorizedto the client; the guard-specific reason is only logged, so the response no longer reveals which guard failed. - Found and fixed with Fable.
v0.1.6May 17, 2026
JwtGuard.generate(user, { claims })now throws whenclaimscarries any of the registered namessub,iat, orexpinstead of silently letting the caller override the subject or token timestamps. Reserved-claim handling is explicit, so a typo in a custom claim cannot mint a token whosesubdoes not match the user passed in. Apps that legitimately want a customsubshould switch to a different identity model rather than rewriting the claim.
v0.1.5May 8, 2026
- Internal release covered by 0.1.6 notes.
v0.1.4April 29, 2026
- Apps that augment
TekirAuthUserwith their own model shape (for exampleextends ModelFields<User>) no longer trip on a baseidtype conflict. The augmentation hook is now field-free so any user model fits.
v0.1.3April 27, 2026
AuthProvidernow wires up a lightweightctx.authinitializer onto the router automatically. Apps no longer have to add a global middleware instart/kernel.tsfor handlers like/registerto callauth.login(...).auth.login()andauth.logout()mutatectx.authin place instead of replacing the object, so destructured handlers like({ auth }) => { await auth.login(user); auth.generate() }keep working after a login swap.- New
attachAuth()middleware exported for apps that prefer wiring it manually instead of relying on the provider.
v0.1.2April 27, 2026
- Guard configs accept a
modelshortcut (any class with a staticfind(id)) and skip the resolver boilerplate. The shipped templates now passmodel: Userdirectly. findUserconfig field renamed toresolveto reflect that the resolver works for any auth subject, not just users (members, accounts, admins, …).- New
AuthModeltype exported for typing custom resolver shortcuts.