Functional Weave
Code in TypeScript

auth.bearer-token@1.0.0

README.md

1,217 bytes · view raw

# auth.bearer-token

`parseBearerToken("Bearer eyJhbGciOi...")` is `"eyJhbGciOi..."`. An API calls
it with the request's `Authorization` header (or null when there is none) and
answers 401 when the result is null; it never throws, because a bad header is
the client's mistake and gets an answer, not a crash.

It follows RFC 6750 section 2.1: the scheme `Bearer`, one or more spaces, then
a `b64token`, which is letters, digits and `- . _ ~ + /`, optionally followed
by `=` padding. The scheme is case-insensitive (`bearer`, `BEARER`), as HTTP
authentication schemes are (RFC 9110 section 11.1). Spaces and tabs around
the whole value are ignored, since HTTP strips them from field values anyway.

Everything else is null: another scheme (`Basic ...`), `Bearer` with no token,
a space or a tab inside the token, `=` anywhere but the end, non-ASCII
characters, or `Bearerabc` with no separating space. A JWT (three base64url
parts joined by dots) is always a valid `b64token`.

This only finds the token; checking it is `auth.jwt` (or
`auth.access-token`, which does both).

Source: RFC 6750, The OAuth 2.0 Authorization Framework: Bearer Token Usage,
section 2.1 (https://www.rfc-editor.org/rfc/rfc6750#section-2.1).