import { validateRegistration } from "#fune/auth.validate-registration@^1";
Suites · auth
User accounts and authentication
Sign-up and login forms, password policy and hashing, login lockout, and signed access tokens (JWT) read from the Authorization header.
34 capabilities (12 core, 22 optional) and 12 gaps, in build order. Put each line in the file that calls it, then fune build.
1. Sign-up and login forms
Check what people type into the account forms, the same way in the browser and the API.
import { validateLogin } from "#fune/auth.validate-login@^1";
import { normaliseEmail } from "#fune/auth.normalise-email@^1";
import { validatePasswordChange } from "#fune/auth.validate-password-change@^1";
2. Passwords
Decide what passwords are acceptable and store them safely.
import { passwordPolicy, checkPassword } from "#fune/auth.password-policy@^1";
import { hashPassword, verifyPassword, passwordNeedsRehash } from "#fune/auth.password-hash@^1";
import { pbkdf2Sha256 } from "#fune/crypto.pbkdf2-sha256@^1";
import { constantTimeEqual } from "#fune/crypto.constant-time-equal@^1";
- breached-passwords Checking passwords against a breach corpus (Have I Been Pwned's range API) is network work; the policy's common-password list is built in.
3. Login protection
Slow down password guessing.
import { loginThrottle } from "#fune/auth.login-throttle@^1";
import { retryAfterSeconds } from "#fune/http.retry-after@^1";
- ip-rate-limiting Rate limiting by IP address across accounts, with its shared counter store (Redis, a database).
4. Tokens
Issue and check signed tokens for an API or a single-page app.
import { issueAccessToken, readAccessToken, confirmAccessToken } from "#fune/auth.access-token@^1";
import { parseBearerToken } from "#fune/auth.bearer-token@^1";
import { signJwt, verifyJwt, decodeJwt } from "#fune/auth.jwt@^1";
import { hmacSha256 } from "#fune/crypto.hmac-sha256@^1";
import { sha256 } from "#fune/crypto.sha256@^1";
import { base64Encode, base64Decode, base64UrlEncode, base64UrlDecode } from "#fune/encoding.base64@^1";
import { countdown } from "#fune/time.countdown@^1";
- sessions Server-side sessions and cookies: storing them, Secure/HttpOnly/SameSite flags, CSRF tokens and expiry are yours.
- asymmetric-jwt RS256/ES256 tokens and JWKS key sets (for third-party identity providers): auth.jwt is HS256 only.
5. Forms in React
Accessible account pages in a React front end (TypeScript only).
import { passwordChecklist, PasswordField } from "#fune/react.form.password-field@^1";
import { TextField } from "#fune/react.form.text-field@^1";
import { errorSummaryItems, ErrorSummary } from "#fune/react.form.error-summary@^1";
import { initialFormState, formReducer, visibleErrors } from "#fune/form.state@^1";
6. Contact details from validation-basics
Check and normalise a person's contact details before storing them.
import { isEmail } from "#fune/validation.email@^1";
import { validatePhoneE164 } from "#fune/validation.phone-e164@^2";
import { validateUkPostcode } from "#fune/validation.uk-postcode@^2";
import { normaliseName } from "#fune/text.normalise-name@^1";
7. Bank details from validation-basics
Check payee and customer bank details before money moves.
import { isIban } from "#fune/validation.iban@^1";
import { validateBic } from "#fune/validation.bic@^1";
import { validateUkSortCodeAccount } from "#fune/validation.uk-sort-code-account@^3";
import { parseUkModulusTable } from "#fune/validation.uk-modulus-table@^1";
8. Identifiers and check digits from validation-basics
Catch mistyped reference numbers by their check digits.
import { isLuhn } from "#fune/validation.luhn@^1";
import { validateUkCompanyNumber } from "#fune/validation.uk-company-number@^2";
import { validateLei } from "#fune/validation.lei@^1";
import { validateGtin } from "#fune/validation.gtin@^1";
9. Displaying sensitive values from validation-basics
Show stored identifiers without exposing them.
import { mask } from "#fune/text.mask@^1";
Gaps
What this kind of app usually needs that Functional Weave does not have yet: write these yourself, or use a service.
- email-verification Sending verification and password-reset emails, and storing their one-time tokens with expiry.
- oauth-social-login OAuth 2.0 / OpenID Connect sign-in with Google, Microsoft, GitHub and the like.
- mfa Second factors: TOTP authenticator codes, SMS codes, passkeys/WebAuthn and recovery codes.
- roles-permissions Roles, permissions and organisation membership: who may do what is yours to model.
- user-storage The users table, unique email index, migrations and account deletion.
- address-lookup Turning a postcode into a list of addresses (Royal Mail PAF or a lookup API) is network work and not in caps.
- email-deliverability Whether a mailbox exists (MX lookups, a confirmation email): validation.email checks the syntax only.
- vocalink-data The Vocalink modulus tables themselves: download them from Pay.UK under its terms; caps parses them but does not ship them.