1.7 KiB
1.7 KiB
WRNexusJS authentication system 0.5 alpha
@wrnexus/auth is a framework-native system built on the WRNexusJS package-runtime architecture.
Architecture
AuthEngineowns identity, credentials, tokens, sessions, recovery, MFA, invitations, OAuth, passkeys, risk, and auditing.AuthStoreisolates persistence.MemoryAuthStoreis for development andSqlAuthStoretargets WRNexusJS database drivers.config.authactivates package routes, auth-session middleware, components, browser schemas, client runtime, ordered migrations, and DevToolbar checks.- Every package endpoint has a route-specific module; path rewriting cannot make an endpoint fall through a shared dispatcher.
createAuthHttpHandlers()remains available for intentionally custom HTTP surfaces.createAuthSecretProtector()protects TOTP and OAuth secrets with a versioned encryption keyring.
Security boundaries
- Password, OTP, token, CAPTCHA, passkey, and MFA verification are server-side.
- Browser schemas improve usability; resolved server schemas remain authoritative.
- Unsafe package routes verify CSRF by default.
- CAPTCHA success is accepted only from server-populated request locals.
- OAuth email linking requires a verified provider email and can be disabled.
- Impersonation is deny-by-default and requires an application policy.
- One-time credentials are expiring, purpose-bound, and single-use.
- Sessions rotate at establishment and support idle and absolute expiration.
- Multi-process passkey deployments provide a shared
PasskeyChallengeStore.
Development version
The package is 0.5.0. Run bun run validate:auth before publishing and read packages/auth/SECURITY.md before production deployment.