838 packages matching “httponly”
proxy-bridge
v0.3.0 · 1 month ago
Next.js App Router proxy bridge for token-based backend authentication with httpOnly cookies, refresh retry, and response sanitization.
No known vulnerabilities
@moriajs/auth
v0.4.39 · 5 months ago
MoriaJS auth — JWT + httpOnly cookies, pluggable auth system
No known vulnerabilities
@wocha/sveltekit
v0.1.3 · 18 days ago
SvelteKit adapter for Wocha authentication (BFF pattern with httpOnly cookies)
No known vulnerabilities
@authagonal/bff
v0.25.2 · 4 days ago
Backend-for-Frontend for SPAs using Authagonal. Runs the OIDC auth-code + PKCE flow server-side, holds tokens in a server-side session, and exposes the browser only an httpOnly cookie. Express + Next.js adapters.
No known vulnerabilities
@wocha/nuxt
v0.1.3 · 18 days ago
Nuxt 3 module for Wocha authentication (BFF pattern with httpOnly cookies)
No known vulnerabilities
@boring-stack-pkg/eslint-plugin-jwt-cookies
v0.1.2 · 2 months ago
ESLint rules that harden auth-cookie defaults (httpOnly, secure) and bcrypt rounds. Defense-in-depth for the cookie-config helper pattern.
No known vulnerabilities
@bota-apps/gql-client
v0.3.0 · 1 month ago
A tiny cookie-credentialed GraphQL client factory built on graphql-request. createGraphQLClient(endpoint) → a client whose every request carries the HttpOnly session cookie.
No known vulnerabilities
@quanticjs/auth-web-bff
v8.4.1 · 1 month ago
BFF authentication module — Keycloak OIDC, Redis sessions, httpOnly cookies
No known vulnerabilities
@invergent/website-widget
v2.14.0 · 1 day ago
AG-UI-compatible TypeScript client for the Surogates public-website channel. Wraps the publishable-key bootstrap, HttpOnly cookie, CSRF double-submit, and SSE streaming behind a standard AbstractAgent so widgets built for AG-UI work out of the box.
No known vulnerabilities
@wocha/remix
v0.1.3 · 18 days ago
Remix / React Router v7 adapter for Wocha authentication (BFF pattern with httpOnly cookies)
No known vulnerabilities
@userkit/nextjs
v0.2.2 · 10 days ago
UserKit for the Next.js App Router: route handlers that keep the session in an httpOnly cookie, server-side session reads, and a route guard.
No known vulnerabilities
@uoj-lk/auth-react
v3.3.1 · 8 days ago
React authentication middleware for University of Jaffna Auth Service with OAuth 2.0 + PKCE, httpOnly cookies, time-bound roles and permissions
No known vulnerabilities
@oauth-spa-kit/server
v2.5.1 · 7 days ago
BFF-pattern OAuth handlers: sealed HttpOnly-cookie sessions + login/callback/refresh/logout route factories, built on Web-standard Request/Response so they drop into Nitro, Next.js route handlers, Cloudflare Workers, or plain Node (via a small adapter).
No known vulnerabilities
is-absolute-url
v5.0.0 · 11 months ago
Check if a URL is absolute
No known vulnerabilities
@swr-login/adapter-cookie
v0.3.0 · 3 months ago
Cookie storage adapter for swr-login (works with BFF pattern for HttpOnly cookies)
No known vulnerabilities
@my-bid/auth
v2.0.0 · 12 days ago
MyBid SSO client surface: session read via /v1/me, refresh + logout gateway calls, sign-in/up URL builders. HttpOnly cookie model — never stores or writes tokens itself.
No known vulnerabilities
@dltech/jwt-auth
v1.0.0 · 15 days ago
Universal JWT authentication: a client-side Auth singleton for web (httpOnly cookies) and mobile (token persistence, network-outage detection) plus a Passport-free NestJS server module (JwtService via jose, BaseAuthGuard, route decorators)
No known vulnerabilities
@unidir/unidir-nextjs
v1.0.24 · 1 month ago
The official UniDir SDK for Next.js applications. This SDK provides secure, server-side OpenID Connect (OIDC) authentication using encrypted `httpOnly` cookies.
No known vulnerabilities
axios-cookie-auth
v1.2.7 · 6 months ago
A lightweight Axios helper for managing httpOnly cookies and automatic token refresh with retries in TypeScript.
No known vulnerabilities
protected-cookie
v1.1.2 · 9 years ago
Middleware for Express.js for setting HttpOnly cookie and get access to existance of this cookie
No known vulnerabilities