Coder Social home page Coder Social logo

casdoor / casdoor-js-sdk Goto Github PK

View Code? Open in Web Editor NEW
30.0 3.0 26.0 205 KB

Javascript client SDK for Casdoor

Home Page: https://github.com/casdoor/casdoor

License: Apache License 2.0

TypeScript 100.00%
auth authn authentication sso oauth oidc casdoor javascript js

casdoor-js-sdk's Introduction

casdoor-js-sdk

NPM version NPM download codebeat badge GitHub Actions GitHub Actions Coverage Status Release Discord

This is Casdoor's SDK for js will allow you to easily connect your application to the Casdoor authentication system without having to implement it from scratch.

Casdoor SDK is very simple to use. We will show you the steps below.

Usage in NPM environment

Installation

# NPM
npm i casdoor-js-sdk

# Yarn
yarn add casdoor-js-sdk

Init SDK

Initialization requires 5 parameters, which are all string type:

Name (in order) Must Description
serverUrl Yes your Casdoor server URL
clientId Yes the Client ID of your Casdoor application
appName Yes the name of your Casdoor application
organizationName Yes the name of the Casdoor organization connected with your Casdoor application
redirectPath No the path of the redirect URL for your Casdoor application, will be /callback if not provided
signinPath No the path of the signin URL for your Casdoor application, will be /api/signin if not provided
import {SDK, SdkConfig} from 'casdoor-js-sdk'

const sdkConfig: SdkConfig = {
    serverUrl: "https://door.casbin.com",
    clientId: "014ae4bd048734ca2dea",
    appName: "app-casnode",
    organizationName: "casbin",
    redirectPath: "/callback",
    signinPath: "/api/signin",
}
const sdk = new SDK(sdkConfig)
// call sdk to handle

Usage in vanilla Javascript

Import and init SDK

Initialization parameters are consistent with the previous node.js section:

<!--init the SDK-->
<script type="module">
  //Import from cdn(you can choose the appropriate cdn source according to your needs), or just from the local(download the casdoor-js-sdk first)
  import SDK from 'https://unpkg.com/casdoor-js-sdk@latest/lib/esm/sdk.js'
  const sdkConfig = {
    serverUrl: "https://door.casbin.com",
    clientId: "014ae4bd048734ca2dea",
    appName: "app-casnode",
    organizationName: "casbin",
    redirectPath: "/callback",
    signinPath: "/api/signin",
  }
  window.sdk = new SDK(sdkConfig)
</script>

Call functions in SDK

<script type="text/javascript">
  function gotoSignUpPage() {
    window.location.href = sdk.getSigninUrl()
  }
</script>

API reference interface

Get sign up url

getSignupUrl(enablePassword)

Return the casdoor url that navigates to the registration screen

Get sign in url

getSigninUrl()

Return the casdoor url that navigates to the login screen

Get user profile page url

getUserProfileUrl(userName, account)

Return the url to navigate to a specific user's casdoor personal page

Get my profile page url

getMyProfileUrl(account)

Sign in

signin(serverUrl, signinPath)

Handle the callback url from casdoor, call the back-end api to complete the login process

Determine whether silent sign-in is being used

isSilentSigninRequested()

We usually use this method to determine if silent login is being used. By default, if the silentSignin parameter is included in the URL and equals one, this method will return true. Of course, you can also use any method you prefer.

silentSignin

silentSignin(onSuccess, onFailure)

First, let's explain the two parameters of this method, which are the callback methods for successful and failed login. Next, I will describe the execution process of this method. We will create a hidden "iframe" element to redirect to the login page for authentication, thereby achieving the effect of silent sign-in.

popupSignin

popupSignin(serverUrl, signinPath)

Popup a window to handle the callback url from casdoor, call the back-end api to complete the login process and store the token in localstorage, then reload the main window. See Demo: casdoor-nodejs-react-example.

OAuth2 PKCE flow sdk (for SPA without backend)

Start the authorization process

Typically, you just need to go to the authorization url to start the process. This example is something that might work in an SPA.

signin_redirect();

You may add additional query parameters to the authorize url by using an optional second parameter:

const additionalParams = {test_param: 'testing'};
signin_redirect(additionalParams);

Trade the code for a token

When you get back here, you need to exchange the code for a token.

sdk.exchangeForAccessToken().then((resp) => {
    const token = resp.access_token;
    // Do stuff with the access token.
});

As with the authorizeUrl method, an optional second parameter may be passed to the exchangeForAccessToken method to send additional parameters to the request:

const additionalParams = {test_param: 'testing'};

sdk.exchangeForAccessToken(additionalParams).then((resp) => {
    const token = resp.access_token;
    // Do stuff with the access token.
});

Parse the access token

Once you have an access token, you can parse it into JWT header and payload.

const result = sdk.parseAccessToken(accessToken);
console.log("JWT algorithm: " + result.header.alg);
console.log("User organization: " + result.payload.owner);
console.log("User name: " + result.payload.name);

Get user info

Once you have an access token, you can use it to get user info.

getUserInfo(accessToken).then((resp) => {
    const userInfo = resp;
    // Do stuff with the user info.
});

A note on Storage

By default, this package will use sessionStorage to persist the pkce_state. On (mostly) mobile devices there's a higher chance users are returning in a different browser tab. E.g. they kick off in a WebView & get redirected to a new tab. The sessionStorage will be empty there.

In this case it you can opt in to use localStorage instead of sessionStorage:

import {SDK, SdkConfig} from 'casdoor-js-sdk'

const sdkConfig = {
  // ...
  storage: localStorage, // any Storage object, sessionStorage (default) or localStorage
}

const sdk = new SDK(sdkConfig)

More examples

To see how to use casdoor frontend SDK with casdoor backend SDK, you can refer to examples below:

casnode: casdoor-js-sdk + casdoor-go-sdk

casdoor-python-vue-sdk-example: casdoor-vue-sdk + casdoor-python-sdk

A more detailed description can be moved to:casdoor-sdk

casdoor-js-sdk's People

Contributors

dacongda avatar erikqqy avatar fabian4 avatar hsluoyz avatar imp2002 avatar jakiuncle avatar jump2cn avatar leo220yuyaodog avatar nekotoxin avatar nodece avatar nomeguy avatar selflocking avatar seriouszyx avatar windspiritsr avatar xiaocode avatar zxilly avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar

casdoor-js-sdk's Issues

JWT Payload type for roles is incorrect

The interface for JwtPayload has the roles property as a list of strings, but the actual value returned seems to be a list of Role objects which look something like:

export interface Role {
  owner: string
  name: string
  createdTime: string
  displayName: string
  description: string
  users: any
  groups: string[]
  roles: any[]
  domains: any[]
  isEnabled: boolean
}

This is giving me some grief in typescript where i'm trying to access role.name in code

roles: string[];

Import Error due to invalid directory in package.json

imageedit_5_5566789286

The directories of files in package.json is of the format lib/cjs/<filename>
while in the package directory they are located at lib/cjs/src/<filename>
which leads to the error Cannot find module 'nodeclub/node_modules/casdoor-js-sdk/lib/cjs/index.js'. Please verify that the package.json has a valid "main" entry

manually changing the package.json then gives correct import results

getSigninUrl() is not taking the Grant Types into account

The implementation of getSigninUrl() currently is hardcoded for Authorization Code Grant Type

public getSigninUrl(): string {
const redirectUri = `${window.location.origin}${this.config.redirectPath}`;
const scope = "read";
const state = this.config.appName;
return `${this.config.serverUrl.trim()}/login/oauth/authorize?client_id=${this.config.clientId}&response_type=code&redirect_uri=${encodeURIComponent(redirectUri)}&scope=${scope}&state=${state}`;
}

  • It has to take grant type into account and construct the appropriate URL for all other relevant Grant Types too.

image

  • Also, there should be a way to retrieve the configured grant types from the CASDoor Server for a given application. (Or better yet, automatically build the URL from one of the configured grant types for the application by talking to the casdoor server)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.