12,863 packages matching “httponly-cookie”
@authagonal/bff
v0.25.2 · 4 days ago
Backend-for-Frontend for SPAs using Authagonal. Runs the OIDC auth-code + PKCE flow server-side, holds tokens in a server-side session, and exposes the browser only an httpOnly cookie. Express + Next.js adapters.
No known vulnerabilities
@invergent/website-widget
v2.14.0 · 1 day ago
AG-UI-compatible TypeScript client for the Surogates public-website channel. Wraps the publishable-key bootstrap, HttpOnly cookie, CSRF double-submit, and SSE streaming behind a standard AbstractAgent so widgets built for AG-UI work out of the box.
No known vulnerabilities
@userkit/nextjs
v0.2.2 · 10 days ago
UserKit for the Next.js App Router: route handlers that keep the session in an httpOnly cookie, server-side session reads, and a route guard.
No known vulnerabilities
@oauth-spa-kit/server
v2.5.1 · 7 days ago
BFF-pattern OAuth handlers: sealed HttpOnly-cookie sessions + login/callback/refresh/logout route factories, built on Web-standard Request/Response so they drop into Nitro, Next.js route handlers, Cloudflare Workers, or plain Node (via a small adapter).
No known vulnerabilities
@my-bid/auth
v2.0.0 · 11 days ago
MyBid SSO client surface: session read via /v1/me, refresh + logout gateway calls, sign-in/up URL builders. HttpOnly cookie model — never stores or writes tokens itself.
No known vulnerabilities
set-cookie-parser
v3.1.2 · 1 month ago
Parses set-cookie headers into objects
No known vulnerabilities
universal-cookie
v8.1.2 · 3 months ago
Universal cookies for JavaScript
No known vulnerabilities
protected-cookie
v1.1.2 · 9 years ago
Middleware for Express.js for setting HttpOnly cookie and get access to existance of this cookie
No known vulnerabilities
@hint/hint-validate-set-cookie-header
v3.0.23 · 1 year ago
hint for best practices related to the usage of the Set-Cookie response header.
No known vulnerabilities
cookies
v0.9.1 · 2 years ago
Cookies, optionally signed using Keygrip.
No known vulnerabilities
cookie-lite
v0.0.2 · 1 year ago
Super lightweight cookie parser and serializer
No known vulnerabilities
cookiefile
v1.0.10 · 9 years ago
Package for operating with Netscape HTTP Cookie File
No known vulnerabilities
is-absolute-url
v5.0.0 · 11 months ago
Check if a URL is absolute
No known vulnerabilities
cookie
v2.0.1 · 1 month ago
HTTP server cookie parsing and serialization
No known vulnerabilities
express-oauth2-middleware
v1.0.2 · 9 years ago
Provides middleware for stateless Bearer token authentication for Express JS. Uses a HttpOnly cookie.
No known vulnerabilities
tough-cookie
v6.0.2 · 1 month ago
RFC6265 Cookies and Cookie Jar for node.js
No known vulnerabilities
cookie-signature
v1.2.2 · 1 year ago
Sign and unsign cookies
No known vulnerabilities
js-cookie
v3.0.8 · 2 months ago
A simple, lightweight JavaScript API for handling cookies
No known vulnerabilities
cookie-es
v3.1.1 · 4 months ago
<!-- automd:badges bundlejs packagephobia codecov -->
No known vulnerabilities
cookiejar
v2.1.4 · 3 years ago
simple persistent cookiejar system
No known vulnerabilities