2.3 KiB
Buffoonery: Tools for the Jester Web Framework
Buffoonery is primarily an opinionated implementation of JWT-based session management a collection of extensions and patterns built around Jester to facilitate the types of API services I tend to write.
Building
JDB Software Packages
Buffoonery depends on a number of packages which are not yet available in he
official Nim repository. The easiest way to get access to these packages is to
add a new PackageList to your nimble configuration for the [JDB Software Nim
packages repository]. The url is
https://git.jdb-software.com/jdb/nim-packages/raw/main/packages.json
Authentication contexts and threads
ApiAuthContext is a value object. Assigning it copies its configuration and
signing-key cache, so each worker can own a context and refresh keys independently.
Copy it before handing it to a worker, and synchronize any access to a context
that another thread may be modifying.
Use a var ApiAuthContext for addSigningKeys, findSigningKey, validateJWT,
and extractValidJwt: lookup and validation can fetch and cache issuer keys.
createSignedJWT, newApiAccessToken, and createSessionCookies also accept
immutable contexts. Existing callers using let for a context that validates
tokens must switch to var; use Option[ApiAuthContext] instead of nil when
absence needs to be represented.
The cache stores keys directly in a Table[string, JwkSet], using the value
semantics provided by jwt_full 0.5.0 or later. Context copies own independent
key caches, and key lookup and signing use the parsed keys directly.
License
Buffoonery is available under two licenses depending on usage.
For private use, non-commercial use, or use in small enterprise (defined as any enterprise bringing in less than $1 million in annual gross profit), Buffoonery is available under the MIT License.
For commercial use in larger enterprises (more than $1 million in annual gross profit), Buffoonery is available under the GNU Affero General Public License v3.0