Authentication and security
On this page
Identity and access rules work alongside business features. OwlMeans Common includes authentication and authorization building blocks that generated applications can use consistently.
Libraries by purpose
| Library or standard | Purpose | Public OwlMeans package |
|---|---|---|
| OpenID Connect | Provide a standard way for an application to use a sign-in provider. | @owlmeans/oidc |
| OAuth | Support delegated authorization with external services. | @owlmeans/server-oauth |
| openid-client | Connect supported OpenID Connect sign-in flows. | @owlmeans/server-oidc-rp |
| jose | Work with supported signed token and cryptographic formats. | @owlmeans/server-oidc-rp |
| @noble/hashes and @scure/base | Provide cryptographic hashing and data-format utilities. | @owlmeans/server-oidc-rp |
| Ajv | Validate the structured data used by security-related interfaces. | @owlmeans/auth-common |
These are public ecosystem dependencies and standards. The exact dependency set of an app depends on its generated project and developed features; not every library listed here is required by every application.
Use this in a project
- Describe the behavior you need in the specification or story.
- Ask the agent to use the project’s existing OwlMeans Common conventions.
- Review the related public package documentation when you want to understand a dependency.
- Try the behavior in the preview and review its access rules.
Define a sales role that may edit assigned contacts and a manager role that may review the team. Test both roles, including direct attempts to access a contact they should not see.
Authentication identifies a user. Authorization enforces what that user may access. Both need to match the product workflow.
Read OwlMeans Tech Concept for the application architecture and continue with another agent for the harness workflow.
Application example
Category: CRM and customer management. Example: a small team CRM with contact ownership and manager access.
Names and marks
Ajv, jose, OpenID Connect, OAuth, openid-client, @noble/hashes, @scure/base names and any associated marks remain with their respective owners or project maintainers. References identify products, standards or source examples. OwlMeans documentation does not imply sponsorship or endorsement by those owners.