Registry / auth-security / simple-auth-basic

simple-auth-basic

JSON →
library2.0.8jsnpmunverified

simple-auth-basic is a lightweight Node.js module designed for parsing HTTP Basic Authorization headers. It extracts the username and password from the 'Authorization' header in an incoming request or a raw header string, returning an object with `name` and `pass` properties. If the header is invalid or missing, it returns `undefined`. The current stable version is 2.0.8. As a focused utility for a well-established standard, its release cadence is generally slow, primarily for maintenance and compatibility updates rather than new features. Its key differentiator is its simplicity and singular focus on parsing the header, leaving credential validation to the application logic, often paired with a timing-safe string comparison library like `tsscmp` for security.

npm install simple-auth-basic
INSTALL
IMPORT
SIG · SIMPLE-AUTH-BASIC
S
simple-auth-basic
auth-securityjavascriptv2.0.8
Install
Import
Disk
Pass rate
0/ 6
Env Coverage0 / 6
glibc
1822
musl
1822
Install & Compatibility
Where this runs
tested against v? · npm install
Install × environment matrix
Each cell = how many times install + import succeeded across repeated harness runs. Partial = flaky.
glibc = Debian/Ubuntu slim · musl = Alpine Linux
musl
node 18226 runs
build_error
glibc
node 18226 runs
build_error
Code
Verified usage

Verified import paths — ran on the pinned version, not inferred.

auth
import auth from 'simple-auth-basic'
const auth = require('simple-auth-basic')
While the README shows CJS `require()`, modern Node.js applications should prefer ESM `import`. This package should be compatible with both.
auth.parse
import auth from 'simple-auth-basic'; auth.parse(headerString)
import { parse } from 'simple-auth-basic'
The `parse` function is a method on the default export, not a named export itself.

Demonstrates setting up a basic Node.js HTTP server that uses simple-auth-basic to parse Authorization headers and perform credential validation. It includes an example of using `tsscmp` for secure password comparison.

import http from 'http'; import auth from 'simple-auth-basic'; import compare from 'tsscmp'; // Often used for timing-safe comparisons const server = http.createServer((req, res) => { const credentials = auth(req); // Basic function to validate credentials (against a user store in real apps) function check (name, pass) { let valid = true; // Using tsscmp to prevent timing attacks valid = compare(name, 'john') && valid; valid = compare(compare(pass, 'secret') && valid); return valid; } if (!credentials || !check(credentials.name, credentials.pass)) { res.statusCode = 401; res.setHeader('WWW-Authenticate', 'Basic realm="Secure Area"'); res.end('Access denied'); } else { res.end(`Welcome, ${credentials.name}! Access granted.`); } }); const port = 3000; server.listen(port, () => { console.log(`Server listening on http://localhost:${port}`); console.log('Try accessing with "john:secret" basic auth.'); });
Debug
Known issues
gotchaThis module only parses the Basic Authorization header. It does not perform any credential validation or database lookups. Developers must implement their own logic for checking usernames and passwords, preferably using timing-safe comparison methods to prevent timing attacks.
fix
Always use a timing-safe string comparison library (e.g., `tsscmp`) when validating user-provided passwords against stored credentials to mitigate timing attacks.
affects: >=0.8
gotchaThe `auth(req)` function expects a standard Node.js HTTP request object. When parsing a header string from other sources (e.g., a custom proxy header or a non-Node.js environment), use `auth.parse(string)` instead.
fix
For raw strings, use `auth.parse(headerString)`. For Node.js `IncomingMessage` objects, use `auth(req)`.
affects: >=0.8
Errors
Common errors & fixes
TypeError: auth is not a function
Attempting to call `auth` directly on a string instead of a request object, or attempting to call `auth.parse` before `auth` is imported correctly.
fix
Ensure `auth` is imported correctly as a default export (`import auth from 'simple-auth-basic'`) and that `auth` is called with a request object (`auth(req)`). For string parsing, use `auth.parse(headerString)`.
ReferenceError: require is not defined in ES module scope
Using CommonJS `require()` syntax in an ESM project (e.g., `"type": "module"` in package.json or `.mjs` files).
fix
Replace `const auth = require('simple-auth-basic')` with `import auth from 'simple-auth-basic'`.
Upgrade
Version history
2.0.8latest on npm
Audit
Dependencies

No dependency data recorded yet.

Agent activity
15 hits · last 30 days
node
12
OpenAI (training)
1
Resources
simple-auth-basic — npm install simple-auth-basic · libregistry