# Buffoonery: Tools for the [Jester Web Framework][jester] Buffoonery is primarily an opinionated implementation of JWT-based session management a collection of extensions and patterns built around Jester to facilitate the types of API services I tend to write. ## Building ### JDB Software Packages Buffoonery depends on a number of packages which are not yet available in he official Nim repository. The easiest way to get access to these packages is to add a new `PackageList` to your [nimble configuration] for the [JDB Software Nim packages repository]. The url is `https://git.jdb-software.com/jdb/nim-packages/raw/main/packages.json` [nimble configuration]: https://github.com/nim-lang/nimble#configuration [JDB Software Nim packages]: https://git.jdb-software.com/jdb/nim-packages ## Authentication contexts and threads `ApiAuthContext` is a value object. Assigning it copies its configuration and signing-key cache, so each worker can own a context and refresh keys independently. Copy it before handing it to a worker, and synchronize any access to a context that another thread may be modifying. Use a `var ApiAuthContext` for `addSigningKeys`, `findSigningKey`, `validateJWT`, and `extractValidJwt`: lookup and validation can fetch and cache issuer keys. `createSignedJWT`, `newApiAccessToken`, and `createSessionCookies` also accept immutable contexts. Existing callers using `let` for a context that validates tokens must switch to `var`; use `Option[ApiAuthContext]` instead of `nil` when absence needs to be represented. The cache stores keys directly in a `Table[string, JwkSet]`, using the value semantics provided by `jwt_full` 0.5.0 or later. Context copies own independent key caches, and key lookup and signing use the parsed keys directly. ## License Buffoonery is available under two licenses depending on usage. For private use, non-commercial use, or use in small enterprise (defined as any enterprise bringing in less than $1 million in annual gross profit), Buffoonery is available under the [MIT License][mit-license]. For commercial use in larger enterprises (more than $1 million in annual gross profit), Buffoonery is available under the [GNU Affero General Public License v3.0][agpl3] [jester]: https://github.com/dom96/jester/ [mit-license]: https://mit-license.org/ [agpl3]: https://www.gnu.org/licenses/agpl-3.0.en.html