Show HN: Comprehensive authentication library for TypeScript
github.com
github.com
Node has decent support for WebCrypto, for example, which renders all usages of node:crypto obsolete.
At this point, I’d also argue that anything not promoting PassKeys as the default method is on the wrong track.
CF workers support it: https://developers.cloudflare.com/workers/runtime-apis/web-c...
Most browsers support it: https://developer.mozilla.org/en-US/docs/Web/API/Crypto
None of the hashes available in webcrypto's digest() are suitable for storing passwords (eg it doesn't support argon2, scrypt, bcrypt, or PBKDF2). They are all SHA family hashes.
https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypt...
You can use PBKDF2 through the deriveKey() function. So you could use that to store passwords. However, this is the least preferred of the acceptable algorithms, and is only recommended for use in scenarios where you must follow a standard that mandates the use of PBKDF2.
Passwords are dumb for most use cases. They’re okay if you follow best practices, the thing is 99% of people don’t. So most people re-use passwords, and if asked to create new ones they append a character or something ineffective.
No thanks, just do a LiDar scan of my face and get me into Netflix please.
This may be dependent on your social. Everyone I know uses password managers, even at work. So they have different passwords for every account and browser/phone extensions or apps to fill them in.
The only one is generally password hashing. At this point, I just run up a service binding to a rust worker and hash it over there.
I checked out the docs and it looks great and you seem to have all the bases covered but I think having a Why in the intro is helpful and comparisons to other solutions like next-auth, supabase auth etc.
I can't remember last time I used anything but JWT at work.
The project explicitly states it as a non-goal, which seems odd to me as I haven't dealt with a REST api that was session based in a decade. Pretty much everything is JWT based.
Honestly, I can't think of any commercial software I've been involved with or API interfaced with that has been written in the past ten years or so that hasn't used JWTs.
Look, i have Oauth2 trauma, and hate ForgeRock, but that doesn't mean they don't have a place
Sidenote: HN generally frowns on creating sock puppet accounts to post identical Show HN under different user names:
If you added that, I've started working on a SCIM client implementation in typescript that could be a nice complement (or just jumpstart) in future (https://github.com/mnahkies/node-scim)
Is this for node.js projects? I thought it would be something for a client side project.
JWT-Based Authentication: We won’t support JWT-based auth unless provided by a third-party plugin.
Right there you've missed something that, say, next-auth covers natively + extensively. What kind of "comprehensiveness" are you targeting?EDIT: Wow, just want to double down on the "gorgeous website" comment after clicking through your docs. Well done, inspiring work! Clear, concise, and eminently navigable.
Here it is: https://fumadocs.vercel.app/
edit: wow, i'm having fun and getting motivated by the creator. glad i went down this Saturday morning rabbit hole.
Sure, there might be some use-cases and I can see why people might opt for it, but not me...
That said, I recently went to add off-the-shelf JS/TS authn to a new SvelteKit app, looking at a few different packages, and was surprised how rough it was to do any method other than sell out your users to adtech companies just a little bit more. (The last off-the-shelf auth framework I used, for Python Flask, was more straightforward to add, and for a rich feature set.) So there seems to be an opportunity to do better.
(I threw out the first attempt, and decided that my most urgent needs, for standing up the beta site and then showing previews for prospective partners, only needed a mix of Nginx HTTP Basic Auth and then simply non-public URLs. Which I could do in minutes, and would also have lower friction for partners to look at. Once authn for normal users percolates back up the project management urgency-sorted backlog, I'll take another quick look at off-the-shelf options, in case there's changes, and then expect I'll probably go with Lucia. Or maybe this Better Auth will be looking like what I want.)