{"id":15040574,"url":"https://github.com/isaac-svi/rex-jwt-middleware","last_synced_at":"2026-02-17T21:02:40.782Z","repository":{"id":143801691,"uuid":"337498317","full_name":"Isaac-Svi/rex-jwt-middleware","owner":"Isaac-Svi","description":"Easily implementable security package for REST Api for an Express server with MongoDB.  Security strategy is build around JWTs.","archived":false,"fork":false,"pushed_at":"2021-08-03T07:53:32.000Z","size":179,"stargazers_count":2,"open_issues_count":0,"forks_count":0,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-10-31T11:26:58.001Z","etag":null,"topics":["jwt","middleware","mongoose","protected-routes","schema"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Isaac-Svi.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-02-09T18:27:29.000Z","updated_at":"2021-08-03T07:53:34.000Z","dependencies_parsed_at":null,"dependency_job_id":"86c3f4a1-ebec-4799-91be-0bb2a9bf80eb","html_url":"https://github.com/Isaac-Svi/rex-jwt-middleware","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Isaac-Svi/rex-jwt-middleware","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Isaac-Svi%2Frex-jwt-middleware","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Isaac-Svi%2Frex-jwt-middleware/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Isaac-Svi%2Frex-jwt-middleware/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Isaac-Svi%2Frex-jwt-middleware/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Isaac-Svi","download_url":"https://codeload.github.com/Isaac-Svi/rex-jwt-middleware/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Isaac-Svi%2Frex-jwt-middleware/sbom","scorecard":{"id":67915,"data":{"date":"2025-08-11","repo":{"name":"github.com/Isaac-Svi/rex-jwt-middleware","commit":"81aca703e46ff3bf8f6cbb2aa62eb6cf5ec237b4"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":1.3,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":0,"reason":"license file not detected","details":["Warn: project does not have a license file"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":0,"reason":"12 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x","Warn: Project is vulnerable to: GHSA-8cf7-32gw-wr33","Warn: Project is vulnerable to: GHSA-hjrf-2m68-5959","Warn: Project is vulnerable to: GHSA-qwph-4952-7xr6","Warn: Project is vulnerable to: GHSA-vxvm-qww3-2fh7","Warn: Project is vulnerable to: GHSA-f825-f98c-gj3g","Warn: Project is vulnerable to: GHSA-h8hf-x3f4-xwgp","Warn: Project is vulnerable to: GHSA-9m93-w8w6-76hh","Warn: Project is vulnerable to: GHSA-m7xq-9374-9rvx","Warn: Project is vulnerable to: GHSA-vg7j-7cwx-8wgw","Warn: Project is vulnerable to: GHSA-p92x-r36w-9395","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-15T03:02:39.330Z","repository_id":143801691,"created_at":"2025-08-15T03:02:39.330Z","updated_at":"2025-08-15T03:02:39.330Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29558100,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-17T20:52:40.164Z","status":"ssl_error","status_checked_at":"2026-02-17T20:48:10.325Z","response_time":100,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["jwt","middleware","mongoose","protected-routes","schema"],"created_at":"2024-09-24T20:44:45.391Z","updated_at":"2026-02-17T21:02:40.765Z","avatar_url":"https://github.com/Isaac-Svi.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# rex-jwt-middleware\n\nrex-jwt-middleware is a package made with the intention to take care of a lot of the boilerplate code for basic user authentication with JWT's, using bcryptjs, jsonwebtoken, cookie, and mongoose.  Best used with package [rex-jwt-client](https://www.npmjs.com/package/rex-jwt-client).\n\n# Contents\n\n- [Installation](#installation)\n- [Setup](#setup)\n  - [Token Setup](#token-setup)\n  - [Token Parameters](#token-parameters)\n  - [User Model](#user-model)\n- [Use](#use)\n  - [Authentication Routes](#auth-routes)\n  - [Refresh Route](#refresh-route)\n  - [Protected Route](#protected-route)\n- [Description](#description)\n\n# Installation \u003ca name=\"installation\"\u003e\u003c/a\u003e\n`npm i rex-jwt-middleware`  \n`yarn add rex-jwt-middleware`\n\n# Setup \u003ca name=\"setup\"\u003e\u003c/a\u003e\n(I'll describe how this all works in the next sections.)\n \n### Add the following next to all other express middleware: \u003ca name=\"token-setup\"\u003e\u003c/a\u003e\n```javascript\nconst { TokenProcessor } = require('rex-jwt-middleware')\n\napp.use(new TokenProcessor({\n  refreshToken: {\n    secret: process.env.REFRESH_TOKEN_SECRET,\n    exp: 20 * 60, // Number of seconds from epoch\n    route: '/api/refresh',\n    cookieName: 'rex',\n  },\n  accessToken: {\n    secret: process.env.ACCESS_TOKEN_SECRET,\n    exp: 10,\n  },\n}))\n```\n#### Parameters: \u003ca name=\"token-parameters\"\u003e\u003c/a\u003e\n`refreshToken`\n| param | description |\n|--|--|\n| secret | Random string used to encrypt our refresh token. |\n| exp | Number of seconds this token is meant to last. |\n| route | Name of route for the cookie containing the refresh token.  This route must match the name of the route used with the `user.refresh` middleware function below. |\n| cookieName | Name of the cookie that will contain the refresh token |\n\n`accessToken`\n| param | description |\n|--|--|\n| secret | Random string used to encrypt our access token. |\n| exp| Number of seconds this token is meant to last. |\n\n\n### Setting up our User model: \u003ca name=\"user-model\"\u003e\u003c/a\u003e\nBefore creating our routes and using our middleware, we need to initialize the User model for our RexUser by providing a schema.  Adding fields to the schema is done in the same way one can add fields to a mongoose schema.\n```javascript\nconst { RexUser } = require('rex-jwt-middleware')\n\nconst user = RexUser({\n  email: {\n    type: String,\n    min: 6,\n    required: true,\n  },\n  password: {\n    type: String,\n    min: 50,\n    required: true,\n  },\n  firstName: {\n    type: String,\n    required: true\n  },\n  // etc.\n})\n```\n# Use \u003ca name=\"use\"\u003e\u003c/a\u003e\n### [](https://github.com/Isaac-Svi/rex-jwt-middleware#routes)Adding authentication/registration routes:\nThese routes can be called anything.  This is just an example:\n```javascript\napp.post('/api/register', user.register)\napp.post('/api/login', user.login)\napp.post('/api/logout', user.logout)\n```\n### Adding a route to refresh an expired access token: \u003ca name=\"refresh-route\"\u003e\u003c/a\u003e\nWe need to add one more route for the refresh token, so that we can send back an access token when the user needs to access protected routes.  This route **must** be the same as the route field in the refreshToken field in the TokenProcessor object above.  Meaning, this route and that can be named whatever you want them to be named, but they have to match.\n```javascript\napp.post('/api/refresh', user.refresh)\n```\n### Setting up a protected route: \u003ca name=\"protected-route\"\u003e\u003c/a\u003e\nProtected routes can only be accessed if the user sends us a valid access token.\n```javascript\napp.get('/secret', user.protect, (req, res) =\u003e {\n  res.send(\"here is some secret content\")\n})\n```\n\n# Description of the process: \u003ca name=\"description\"\u003e\u003c/a\u003e\nThis package uses two JWT's to carry out authentication, an access token and a refresh token.  When a user logs into the site, they receive these two tokens.  The access token can be stored either in memory or localStorage, and the refresh token gets stored in an HTTP only cookie.  \n\nThe access token is what allows a user to access protected routes.  Once the access token expires, as long as the refresh token hasn't expired, the refresh route can be used to get a new access token before accessing a protected route.","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fisaac-svi%2Frex-jwt-middleware","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fisaac-svi%2Frex-jwt-middleware","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fisaac-svi%2Frex-jwt-middleware/lists"}