forked from auth0/node-jwks-rsa
-
Notifications
You must be signed in to change notification settings - Fork 0
/
server.js
78 lines (68 loc) · 1.63 KB
/
server.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
const Hapi = require('hapi');
const good = require('good');
const jwt = require('hapi-auth-jwt2');
const logger = require('debug')('hapi');
const jwksRsa = require('../../src');
const jwksHost = process.env.JWKS_HOST;
const audience = process.env.AUDIENCE;
const issuer = process.env.ISSUER;
// Fake validation, accept any authenticated user.
const validateUser = (decoded, request, callback) => {
logger('Validating user:', decoded);
if (decoded && decoded.sub) {
return callback(null, true);
}
return callback(null, false);
};
// Start the server.
const server = new Hapi.Server({ debug: { log: [ 'error' ] } });
server.connection({ port: 4001 });
server.register(jwt, (err) => {
if (err) {
logger(err);
}
server.auth.strategy('jwt', 'jwt', {
complete: true,
key: jwksRsa.hapiJwt2Key({
cache: true,
rateLimit: true,
jwksRequestsPerMinute: 2,
jwksUri: `${jwksHost}/.well-known/jwks.json`
}),
validateFunc: validateUser,
verifyOptions: {
audience: audience,
issuer: issuer,
algorithms: [ 'RS256' ]
}
});
server.auth.default('jwt');
server.route([
{
method: 'GET',
path: '/me',
config: { auth: 'jwt' },
handler: (request, reply) => {
// This is the user object
reply(request.auth.credentials);
}
}
]);
});
// Logging.
const options = {
reporters: {
console: [
{ module: 'good-console' },
'stdout'
]
}
};
server.register({ register: good, options }, (err) => {
if (err) {
return logger(err);
}
server.start(() => {
logger('Server running at:', server.info.uri);
});
});