Files
buffoonery/README.md
T

55 lines
2.3 KiB
Markdown

# Buffoonery: Tools for the [Jester Web Framework][jester]
Buffoonery is primarily an opinionated implementation of JWT-based session
management
a collection of extensions and patterns built around Jester to
facilitate the types of API services I tend to write.
## Building
### JDB Software Packages
Buffoonery depends on a number of packages which are not yet available in he
official Nim repository. The easiest way to get access to these packages is to
add a new `PackageList` to your [nimble configuration] for the [JDB Software Nim
packages repository]. The url is
`https://git.jdb-software.com/jdb/nim-packages/raw/main/packages.json`
[nimble configuration]: https://github.com/nim-lang/nimble#configuration
[JDB Software Nim packages]: https://git.jdb-software.com/jdb/nim-packages
## Authentication contexts and threads
`ApiAuthContext` is a value object. Assigning it copies its configuration and
signing-key cache, so each worker can own a context and refresh keys independently.
Copy it before handing it to a worker, and synchronize any access to a context
that another thread may be modifying.
Use a `var ApiAuthContext` for `addSigningKeys`, `findSigningKey`, `validateJWT`,
and `extractValidJwt`: lookup and validation can fetch and cache issuer keys.
`createSignedJWT`, `newApiAccessToken`, and `createSessionCookies` also accept
immutable contexts. Existing callers using `let` for a context that validates
tokens must switch to `var`; use `Option[ApiAuthContext]` instead of `nil` when
absence needs to be represented.
The cache stores keys directly in a `Table[string, JwkSet]`, using the value
semantics provided by `jwt_full` 0.5.0 or later. Context copies own independent
key caches, and key lookup and signing use the parsed keys directly.
## License
Buffoonery is available under two licenses depending on usage.
For private use, non-commercial use, or use in small enterprise (defined as any
enterprise bringing in less than $1 million in annual gross profit), Buffoonery
is available under the [MIT License][mit-license].
For commercial use in larger enterprises (more than $1 million in annual
gross profit), Buffoonery is available under the [GNU Affero General Public
License v3.0][agpl3]
[jester]: https://github.com/dom96/jester/
[mit-license]: https://mit-license.org/
[agpl3]: https://www.gnu.org/licenses/agpl-3.0.en.html