diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index f3343415f0..7f3c8671de 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1858,6 +1858,7 @@ /types/jsonstream/ @Bartvds /types/jsontoxml/ @benstevens48 /types/jsonwebtoken/ @SomaticIT @danielheim @brikou +/types/jsonwebtoken-promisified @aneilbaboo /types/jspdf/ @amberjs /types/jsqrcode/ @lordazzi /types/jsrender/ @zakki diff --git a/types/jsonwebtoken-promisified/index.d.ts b/types/jsonwebtoken-promisified/index.d.ts new file mode 100644 index 0000000000..80f28e6528 --- /dev/null +++ b/types/jsonwebtoken-promisified/index.d.ts @@ -0,0 +1,188 @@ +// Type definitions for jsonwebtoken-promisified 1.0 +// Project: https://github.com/joepie91/node-jsonwebtoken-promisified +// Definitions by: Maxime LUCE , +// Daniel Heim , +// Brice BERNARD +// Aneil Mallavarapu +// Definitions: https://github.com/DefinitelyTyped/DefinitelyTyped +// TypeScript Version: 2.2 + +/// + +export class JsonWebTokenError extends Error { + inner: Error; + + constructor(message: string, error?: Error); +} + +export class TokenExpiredError extends JsonWebTokenError { + expiredAt: number; + + constructor(message: string, expiredAt: number); +} + +export class NotBeforeError extends JsonWebTokenError { + date: Date; + + constructor(message: string, date: Date); +} + +export interface SignOptions { + /** + * Signature algorithm. Could be one of these values : + * - HS256: HMAC using SHA-256 hash algorithm (default) + * - HS384: HMAC using SHA-384 hash algorithm + * - HS512: HMAC using SHA-512 hash algorithm + * - RS256: RSASSA using SHA-256 hash algorithm + * - RS384: RSASSA using SHA-384 hash algorithm + * - RS512: RSASSA using SHA-512 hash algorithm + * - ES256: ECDSA using P-256 curve and SHA-256 hash algorithm + * - ES384: ECDSA using P-384 curve and SHA-384 hash algorithm + * - ES512: ECDSA using P-521 curve and SHA-512 hash algorithm + * - none: No digital signature or MAC value included + */ + algorithm?: string; + keyid?: string; + /** {string} - expressed in seconds or a string describing a time span [zeit/ms](https://github.com/zeit/ms.js). Eg: 60, "2 days", "10h", "7d" */ + expiresIn?: string | number; + /** {string} - expressed in seconds or a string describing a time span [zeit/ms](https://github.com/zeit/ms.js). Eg: 60, "2 days", "10h", "7d" */ + notBefore?: string | number; + audience?: string | string[]; + subject?: string; + issuer?: string; + jwtid?: string; + noTimestamp?: boolean; + header?: object; + encoding?: string; +} + +export interface VerifyOptions { + algorithms?: string[]; + audience?: string | string[]; + clockTimestamp?: number; + clockTolerance?: number; + issuer?: string | string[]; + ignoreExpiration?: boolean; + ignoreNotBefore?: boolean; + jwtid?: string; + subject?: string; + /** + * @deprecated + * {string} - Max age of token + */ + maxAge?: string; +} + +export interface DecodeOptions { + complete?: boolean; + json?: boolean; +} + +export type VerifyCallback = ( + err: JsonWebTokenError | NotBeforeError | TokenExpiredError, + decoded: object | string +) => void; + +export type SignCallback = (err: Error, encoded: string) => void; + +export type Secret = string | Buffer | { key: string; passphrase: string }; + +/** + * Synchronously sign the given payload into a JSON Web Token string + * @param payload - Payload to sign, could be an literal, buffer or string + * @param secretOrPrivateKey - Either the secret for HMAC algorithms, or the PEM encoded private key for RSA and ECDSA. + * @param [options] - Options for the signature + * @returns The JSON Web Token string + */ +export function sign( + payload: string | Buffer | object, + secretOrPrivateKey: Secret, + options?: SignOptions, +): string; + +/** + * Sign the given payload into a JSON Web Token string + * @param payload - Payload to sign, could be an literal, buffer or string + * @param secretOrPrivateKey - Either the secret for HMAC algorithms, or the PEM encoded private key for RSA and ECDSA. + * @param options - Options for the signature + * @param callback - Callback to get the encoded token on + */ +export function sign( + payload: string | Buffer | object, + secretOrPrivateKey: Secret, + callback: SignCallback, +): void; +export function sign( + payload: string | Buffer | object, + secretOrPrivateKey: Secret, + options: SignOptions, + callback: SignCallback, +): void; + +/** + * Sign the given payload asynchronously into a JSON Web Token String + * @param payload - Payload to sign, could be an literal, buffer or string + * @param secretOrPrivateKey - Either the secret for HMAC algorithms, or the PEM encoded private key for RSA and ECDSA. + * @param [options] - Options for the signature + * @returns A promise providing JSON Web Token string + */ +export function signAsync( + payload: string | Buffer | object, + secretOrPrivateKey: Secret, + options?: SignOptions +): Promise; + +/** + * Synchronously verify given token using a secret or a public key to get a decoded token + * @param token - JWT string to verify + * @param secretOrPublicKey - Either the secret for HMAC algorithms, or the PEM encoded public key for RSA and ECDSA. + * @param [options] - Options for the verification + * @returns The decoded token. + */ +export function verify( + token: string, + secretOrPublicKey: string | Buffer, + options?: VerifyOptions, +): object | string; + +/** + * Asynchronously verify given token using a secret or a public key to get a decoded token + * @param token - JWT string to verify + * @param secretOrPublicKey - Either the secret for HMAC algorithms, or the PEM encoded public key for RSA and ECDSA. + * @param options - Options for the verification + * @param callback - Callback to get the decoded token on + */ +export function verify( + token: string, + secretOrPublicKey: string | Buffer, + callback?: VerifyCallback +): void; +export function verify( + token: string, + secretOrPublicKey: string | Buffer, + options: VerifyOptions, + callback?: VerifyCallback +): void; + +/** + * Asynchronously verify given token using a secret or a public key to get a decoded token + * @param token - the JWT string to verify + * @param secretOrPublicKey - Either the secret for HMAC algorithms, or the PEM encoded public key for RSA and ECDSA. + * @returns - Promise returning the decoded token + */ +export function verifyAsync( + token: string, + secretOrPublicKey: string | Buffer, + options?: VerifyOptions +): Promise; + +/** + * Returns the decoded payload without verifying if the signature is valid. + * @param token - JWT string to decode + * @param [options] - Options for decoding + * @returns The decoded Token + */ +export function decode( + token: string, + options?: DecodeOptions, +): null | { [key: string]: any } | string; diff --git a/types/jsonwebtoken-promisified/jsonwebtoken-promisified-tests.ts b/types/jsonwebtoken-promisified/jsonwebtoken-promisified-tests.ts new file mode 100644 index 0000000000..bfa282bdee --- /dev/null +++ b/types/jsonwebtoken-promisified/jsonwebtoken-promisified-tests.ts @@ -0,0 +1,148 @@ +/** + * Test suite created by Maxime LUCE + * + * Created by using code samples from https://github.com/auth0/node-jsonwebtoken. + */ + +import jwt = require("jsonwebtoken-promisified"); +import fs = require("fs"); + +let token: string; +let cert: Buffer; + +interface TestObject { + foo: string; +} + +const testObject = { foo: "bar" }; + +/** + * jwt.sign + * https://github.com/auth0/node-jsonwebtoken#usage + */ +// sign with default (HMAC SHA256) +token = jwt.sign(testObject, "shhhhh"); + +// sign with default (HMAC SHA256) and single audience +token = jwt.sign(testObject, "shhhhh", { audience: "theAudience" }); + +// sign with default (HMAC SHA256) and multiple audiences +token = jwt.sign(testObject, "shhhhh", { + audience: ["audience1", "audience2"], +}); + +// sign with default (HMAC SHA256) and a keyid +token = jwt.sign(testObject, "shhhhh", { keyid: "theKeyId" }); + +// sign with RSA SHA256 +cert = fs.readFileSync("private.key"); // get private key +token = jwt.sign(testObject, cert, { algorithm: "RS256" }); + +// sign with encrypted RSA SHA256 private key (only PEM encoding is supported) +const privKey: Buffer = fs.readFileSync("encrypted_private.key"); // get private key +const secret = { key: privKey.toString(), passphrase: "keypwd" }; +token = jwt.sign(testObject, secret, { algorithm: "RS256" }); // the algorithm option is mandatory in this case + +// sign asynchronously +jwt.sign(testObject, cert, { algorithm: "RS256" }, ( + err: Error, + token: string, +) => { + console.log(token); +}); + +jwt.signAsync(testObject, cert, { algorithm: "RS256" }).then( + (token: string) => console.log(token) +); +/** + * jwt.verify + * https://github.com/auth0/node-jsonwebtoken#jwtverifytoken-secretorpublickey-options-callback + */ +// verify a token symmetric +jwt.verify(token, "shhhhh", ( + err: jwt.JsonWebTokenError | jwt.NotBeforeError | jwt.TokenExpiredError, + decoded: object | string +) => { + const result = decoded as TestObject; + + console.log(result.foo); // bar +}); +jwt.verifyAsync(token, "shhhhh").then(decoded => { + const result = decoded as TestObject; + + console.log(result.foo); // bar +}); + +// use external time for verifying +jwt.verify(token, 'shhhhh', { clockTimestamp: 1 }, (err, decoded) => { + const result = decoded as TestObject; + + console.log(result.foo); // bar +}); +jwt.verifyAsync(token, 'shhhhh', { clockTimestamp: 1 }).then(decoded => { + const result = decoded as TestObject; + + console.log(result.foo); // bar +}); + +// invalid token +jwt.verify(token, "wrong-secret", (err, decoded) => { + // err + // decoded undefined +}); + +// verify a token asymmetric +cert = fs.readFileSync("public.pem"); // get public key +jwt.verify(token, cert, (err, decoded) => { + const result = decoded as TestObject; + + console.log(result.foo); // bar +}); + +jwt.verifyAsync(token, cert).then(decoded => { + const result = decoded as TestObject; + console.log(result.foo); // bar +}); + +// verify audience +cert = fs.readFileSync("public.pem"); // get public key +jwt.verify(token, cert, { audience: "urn:foo" }, (err, decoded) => { + // if audience mismatch, err == invalid audience +}); + +// verify issuer +cert = fs.readFileSync("public.pem"); // get public key +jwt.verify(token, cert, { audience: "urn:foo", issuer: "urn:issuer" }, ( + err, + decoded, +) => { + // if issuer mismatch, err == invalid issuer +}); + +// verify algorithm +cert = fs.readFileSync("public.pem"); // get public key +jwt.verify(token, cert, { algorithms: ["RS256"] }, (err, decoded) => { + // if algorithm mismatch, err == invalid algorithm +}); + +// verify without expiration check +cert = fs.readFileSync("public.pem"); // get public key +jwt.verify(token, cert, { ignoreExpiration: true }, (err, decoded) => { + // if ignoreExpration == false and token is expired, err == expired token +}); + +/** + * jwt.decode + * https://github.com/auth0/node-jsonwebtoken#jwtdecodetoken + */ +let decoded = jwt.decode(token); + +decoded = jwt.decode(token, { complete: false }); + +if (decoded !== null && typeof decoded === "object") { + console.log(decoded.foo); +} + +decoded = jwt.decode(token, { json: false }); + +decoded = jwt.decode(token, { complete: false, json: false }); diff --git a/types/jsonwebtoken-promisified/tsconfig.json b/types/jsonwebtoken-promisified/tsconfig.json new file mode 100644 index 0000000000..0b6053d82b --- /dev/null +++ b/types/jsonwebtoken-promisified/tsconfig.json @@ -0,0 +1,23 @@ +{ + "compilerOptions": { + "module": "commonjs", + "lib": [ + "es6" + ], + "noImplicitAny": true, + "noImplicitThis": true, + "strictNullChecks": false, + "strictFunctionTypes": true, + "baseUrl": "../", + "typeRoots": [ + "../" + ], + "types": [], + "noEmit": true, + "forceConsistentCasingInFileNames": true + }, + "files": [ + "index.d.ts", + "jsonwebtoken-promisified-tests.ts" + ] +} \ No newline at end of file diff --git a/types/jsonwebtoken-promisified/tslint.json b/types/jsonwebtoken-promisified/tslint.json new file mode 100644 index 0000000000..f93cf8562a --- /dev/null +++ b/types/jsonwebtoken-promisified/tslint.json @@ -0,0 +1,3 @@ +{ + "extends": "dtslint/dt.json" +}