1,010 packages matching “httponly”
@boring-stack-pkg/eslint-plugin-jwt-cookies
v0.1.2 · 4 months ago
ESLint rules that harden auth-cookie defaults (httpOnly, secure) and bcrypt rounds. Defense-in-depth for the cookie-config helper pattern.
No known vulnerabilities
@userkit/nextjs
v0.9.0 · 20 days ago
UserKit for the Next.js App Router: route handlers that keep the session in an httpOnly cookie, server-side session reads, and a route guard.
No known vulnerabilities
@fonlan/dsh-web-auth
v0.1.9 · 1 day ago
DSH web plugin: password-gate authentication (login page + HttpOnly signed cookie) for exposing dsh web behind a reverse proxy
No known vulnerabilities
proxy-bridge
v1.1.0 · 19 days ago
Next.js App Router proxy bridge for token-based backend authentication with httpOnly cookies, refresh retry, and response sanitization.
No known vulnerabilities
@blokjs/session
v2.5.4 · 7 hours ago
Signed, HttpOnly server-side sessions for Blok — pluggable store (memory / sqlite / postgres / redis), session.get/set/forget/regenerate nodes, and the inertia.session middleware.
No known vulnerabilities
@thinkgrid/react-starter-auth
v1.0.2 · 1 month ago
Secure JWT authentication for React and Next.js — HttpOnly server sessions, verified tokens, CSRF built in.
No known vulnerabilities
@invergent/website-widget
v2.16.8 · 2 days ago
AG-UI-compatible TypeScript client for the Surogates public-website channel. Wraps the publishable-key bootstrap, HttpOnly cookie, CSRF double-submit, and SSE streaming behind a standard AbstractAgent so widgets built for AG-UI work out of the box.
No known vulnerabilities
@moriajs/auth
v0.4.39 · 7 months ago
MoriaJS auth — JWT + httpOnly cookies, pluggable auth system
No known vulnerabilities
@authagonal/bff
v0.29.0 · 16 days ago
Backend-for-Frontend for SPAs using Authagonal. Runs the OIDC auth-code + PKCE flow server-side, holds tokens in a server-side session, and exposes the browser only an httpOnly cookie. Express + Next.js adapters.
No known vulnerabilities
dsh-webui-oauth
v0.6.6 · 12 days ago
WebUI authentication plugin for DeepSeek Harness: password or OIDC/SSO login enforced at the HTTP/transport layer, with server-side sessions, HttpOnly cookies and audit logging. Zero dependencies.
No known vulnerabilities
is-absolute-url
v5.0.0 · 1 year ago
Check if a URL is absolute
No known vulnerabilities
@quanticjs/auth-web-bff
v8.4.1 · 3 months ago
BFF authentication module — Keycloak OIDC, Redis sessions, httpOnly cookies
No known vulnerabilities
@tuwaio/siwx-server
v0.4.1 · 12 hours ago
L2 server package of SIWX (TUWA): backend verification of CAIP-122 sign-ins for EVM and Solana, single-use nonce and session stores, HttpOnly cookie helpers and Next.js App Router handlers.
No known vulnerabilities
@xemahq/oidc-session-nest
v3.0.0 · 5 hours ago
Server-side OIDC session for a NestJS backend-for-frontend: the browser holds one httpOnly cookie and never a Xema token. Performs the authorization-code exchange, keeps the token set in a session store the application owns, refreshes it under a lease so
No known vulnerabilities
@swr-login/adapter-cookie
v0.3.0 · 4 months ago
Cookie storage adapter for swr-login (works with BFF pattern for HttpOnly cookies)
No known vulnerabilities
protected-cookie
v1.1.2 · 9 years ago
Middleware for Express.js for setting HttpOnly cookie and get access to existance of this cookie
No known vulnerabilities
@uoj-lk/auth-react
v3.4.0 · 1 month ago
React authentication middleware for University of Jaffna Auth Service with OAuth 2.0 + PKCE, httpOnly cookies, time-bound roles and permissions
No known vulnerabilities
@unidir/unidir-nextjs
v1.0.24 · 3 months ago
The official UniDir SDK for Next.js applications. This SDK provides secure, server-side OpenID Connect (OIDC) authentication using encrypted `httpOnly` cookies.
No known vulnerabilities
@yannvr/auth
v1.0.4 · 6 months ago
Shared passkey auth (WebAuthn + HttpOnly cookies) for Next.js apps
No known vulnerabilities
@my-bid/auth
v8.0.0 · 1 hour ago
MyBid SSO client surface: session read via /v1/me, refresh + logout gateway calls, sign-in/up URL builders. HttpOnly cookie model — never stores or writes tokens itself.
No known vulnerabilities