Compare commits
89
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3f0a3124f3 | ||
|
|
949032ee09 | ||
|
|
3c58d17aba | ||
|
|
07954bb20b | ||
|
|
275af27a81 | ||
|
|
c63d9ea7ac | ||
|
|
8518ea18a7 | ||
|
|
18aaf5a1b8 | ||
|
|
9543a81d76 | ||
|
|
13f00cf476 | ||
|
|
9e28754bb1 | ||
|
|
095d227a13 | ||
|
|
889a1a08f5 | ||
|
|
6d7eedc213 | ||
|
|
bfdfb2ca38 | ||
|
|
17c772e839 | ||
|
|
73b5161a67 | ||
|
|
95eb75ac77 | ||
|
+2 |
01fd5237f5 | ||
|
|
6fd7497c15 | ||
|
|
25616ca794 | ||
|
|
2a345172a3 | ||
|
|
8cb002259a | ||
|
|
436d9baba2 | ||
|
|
e417f6ac64 | ||
|
|
65ea87425c | ||
|
|
0aea03e418 | ||
|
|
d8b488bbc9 | ||
|
|
cb0ef6a6a2 | ||
|
|
c377290b27 | ||
|
|
35bddd69c5 | ||
|
|
34be385a5c | ||
|
|
79c9e130fd | ||
|
|
9c884e2f55 | ||
|
|
2e21b52b97 | ||
|
|
e3f44905ca | ||
|
|
c47927708a | ||
|
|
4c511f0310 | ||
|
|
b2728ec6f2 | ||
|
|
663759975d | ||
|
|
f1971ffe36 | ||
|
|
8b134bbb55 | ||
|
|
8a20aa5825 | ||
|
|
112863ecce | ||
|
|
863049dc0c | ||
|
|
802ba8c5a9 | ||
|
|
e36ebe2243 | ||
|
|
c52e3beac1 | ||
|
|
f0250a77cd | ||
|
|
d4be6479db | ||
|
|
c67b287764 | ||
|
|
7ac4e6ba4e | ||
|
|
c494db87cb | ||
|
|
1932d601c1 | ||
|
|
846a3503fe | ||
|
|
3e7f9cb946 | ||
|
|
83526c519a | ||
|
|
2e01627c99 | ||
|
|
7b52c6bba0 | ||
|
|
e024d78ed0 | ||
|
|
a2002d1637 | ||
|
|
607ab7e860 | ||
|
|
f27989741a | ||
|
|
b2be63ada4 | ||
|
|
eee200f8d4 | ||
|
|
817ab2249f | ||
|
|
173777ade4 | ||
|
|
838233075a | ||
|
|
cabfc29119 | ||
|
|
f02570db88 | ||
|
|
c6b025e844 | ||
|
|
332a14552b | ||
|
|
c894270401 | ||
|
|
595815dc3e | ||
|
|
b959cafccc | ||
|
|
4cf0aede0e | ||
|
|
6cf298a29a | ||
|
|
62b2508a6c | ||
|
|
c3967b798e | ||
|
|
588897d1b0 | ||
|
|
862905e161 | ||
|
|
5f81e246f2 | ||
|
|
1b052d63e9 | ||
|
|
a3f6878649 | ||
|
|
74a92dcb7d | ||
|
|
38fc0b796a | ||
|
|
ef76a96c2d | ||
|
|
2667706d8d | ||
|
|
047fbe2918 |
@@ -16,9 +16,6 @@
|
||||
"baseBranch": "main",
|
||||
"updateInternalDependencies": "patch",
|
||||
"ignore": [
|
||||
"e2e-cra-5",
|
||||
"e2e-next-13",
|
||||
"e2e-vite-3",
|
||||
"bundlers-esbuild",
|
||||
"bundlers-vite",
|
||||
"bundlers-webpack",
|
||||
|
||||
@@ -22,13 +22,13 @@ We use [Turborepo](https://turborepo.org/docs/getting-started) to manage the mon
|
||||
|
||||
You can see a quick outline of each of the projects within this repo below, each living within the [/packages](/packages) directory:
|
||||
|
||||
| Package | Description | Latest Version |
|
||||
| ------------------------------ | -------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| [/sdk](./packages/sdk) | Best in class web3 SDK for Browser, Node and Mobile apps | <a href="https://www.npmjs.com/package/@thirdweb-dev/sdk"><img src="https://img.shields.io/npm/v/@thirdweb-dev/sdk?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/react](./packages/react) | Ultimate collection of React hooks for your web3 apps | <a href="https://www.npmjs.com/package/@thirdweb-dev/react"><img src="https://img.shields.io/npm/v/@thirdweb-dev/react?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/auth](./packages/auth) | Best in class wallet authentication for Node backends | <a href="https://www.npmjs.com/package/@thirdweb-dev/auth"><img src="https://img.shields.io/npm/v/@thirdweb-dev/auth?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/storage](./packages/storage) | Best in class decentralized storage SDK for Browser and Node | <a href="https://www.npmjs.com/package/@thirdweb-dev/storage"><img src="https://img.shields.io/npm/v/@thirdweb-dev/storage?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/cli](./packages/cli) | Publish and deploy smart contracts without dealing with private keys | <a href="https://www.npmjs.com/package/thirdweb"><img src="https://img.shields.io/npm/v/thirdweb?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| Package | Description | Latest Version |
|
||||
| ------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| [/sdk](./legacy_packages/sdk) | Best in class web3 SDK for Browser, Node and Mobile apps | <a href="https://www.npmjs.com/package/@thirdweb-dev/sdk"><img src="https://img.shields.io/npm/v/@thirdweb-dev/sdk?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/react](./legacy_packages/react) | Ultimate collection of React hooks for your web3 apps | <a href="https://www.npmjs.com/package/@thirdweb-dev/react"><img src="https://img.shields.io/npm/v/@thirdweb-dev/react?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/auth](./legacy_packages/auth) | Best in class wallet authentication for Node backends | <a href="https://www.npmjs.com/package/@thirdweb-dev/auth"><img src="https://img.shields.io/npm/v/@thirdweb-dev/auth?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/storage](./legacy_packages/storage) | Best in class decentralized storage SDK for Browser and Node | <a href="https://www.npmjs.com/package/@thirdweb-dev/storage"><img src="https://img.shields.io/npm/v/@thirdweb-dev/storage?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/cli](./legacy_packages/cli) | Publish and deploy smart contracts without dealing with private keys | <a href="https://www.npmjs.com/package/thirdweb"><img src="https://img.shields.io/npm/v/thirdweb?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
|
||||
## How to contribute
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
name: Build, Lint & Test
|
||||
name: Build, Lint & Test & Benchmark
|
||||
|
||||
on:
|
||||
push:
|
||||
@@ -8,6 +8,7 @@ on:
|
||||
# trigger on merge group as well (merge queue)
|
||||
merge_group:
|
||||
types: [checks_requested]
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
@@ -111,12 +112,15 @@ jobs:
|
||||
path: ./*
|
||||
key: ${{ github.sha }}-${{ github.run_number }}
|
||||
|
||||
- name: Set up foundry
|
||||
uses: foundry-rs/foundry-toolchain@v1
|
||||
|
||||
- run: pnpm test
|
||||
|
||||
- name: Upload coverage reports to Codecov
|
||||
uses: codecov/codecov-action@v3
|
||||
with:
|
||||
files: ./packages/sdk/coverage/evm/lcov.info
|
||||
files: ./legacy_packages/sdk/coverage/evm/lcov.info,./packages/thirdweb/coverage/lcov.info
|
||||
|
||||
e2e:
|
||||
timeout-minutes: 15
|
||||
@@ -155,3 +159,35 @@ jobs:
|
||||
env:
|
||||
NODE_OPTIONS: "--max_old_space_size=4096"
|
||||
CLI_E2E_API_KEY: ${{ secrets.CLI_E2E_API_KEY }}
|
||||
|
||||
benchmark:
|
||||
timeout-minutes: 15
|
||||
name: "Benchmark"
|
||||
runs-on: ubuntu-latest-16
|
||||
needs: build
|
||||
steps:
|
||||
- name: Setup node
|
||||
uses: actions/setup-node@v3
|
||||
with:
|
||||
node-version: 20
|
||||
check-latest: true
|
||||
|
||||
- uses: pnpm/action-setup@v2
|
||||
with:
|
||||
version: 8
|
||||
|
||||
- uses: actions/cache@v3
|
||||
timeout-minutes: 5
|
||||
id: restore-build
|
||||
with:
|
||||
path: ./*
|
||||
key: ${{ github.sha }}-${{ github.run_number }}
|
||||
|
||||
- name: Set up foundry
|
||||
uses: foundry-rs/foundry-toolchain@v1
|
||||
|
||||
- name: Run benchmarks
|
||||
uses: CodSpeedHQ/action@v2
|
||||
with:
|
||||
token: ${{ secrets.CODSPEED_TOKEN }}
|
||||
run: "pnpm bench"
|
||||
|
||||
@@ -10,8 +10,14 @@ on:
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
# cancel any previous runs if they were started before this one
|
||||
cancel-in-progress: true
|
||||
|
||||
env:
|
||||
TURBO_TOKEN: ${{ secrets.TURBO_TOKEN }}
|
||||
TURBO_TEAM: ${{ secrets.TURBO_TEAM }}
|
||||
TW_SECRET_KEY: ${{ secrets.TW_SECRET_KEY }}
|
||||
|
||||
jobs:
|
||||
release-artifacts:
|
||||
timeout-minutes: 15
|
||||
@@ -37,7 +43,7 @@ jobs:
|
||||
|
||||
- name: Generate Docs
|
||||
run: |
|
||||
cd packages/sdk
|
||||
cd legacy_packages/sdk
|
||||
pnpm generate-docs
|
||||
cd ../react-core
|
||||
pnpm generate-docs
|
||||
@@ -53,12 +59,13 @@ jobs:
|
||||
git config --local user.email "[email protected]"
|
||||
git config --local user.name "GitHub Action"
|
||||
git status
|
||||
git add packages/react/typedoc/documentation.json.gz
|
||||
git add packages/react-core/typedoc/documentation.json.gz
|
||||
git add packages/react-native/typedoc/documentation.json.gz
|
||||
git add packages/sdk/typedoc/documentation.json.gz
|
||||
git add packages/storage/typedoc/documentation.json.gz
|
||||
git add packages/wallets/typedoc/documentation.json.gz
|
||||
git add legacy_packages/react/typedoc/documentation.json.gz
|
||||
git add legacy_packages/react-core/typedoc/documentation.json.gz
|
||||
git add legacy_packages/react-native/typedoc/documentation.json.gz
|
||||
git add legacy_packages/sdk/typedoc/documentation.json.gz
|
||||
git add legacy_packages/storage/typedoc/documentation.json.gz
|
||||
git add legacy_packages/wallets/typedoc/documentation.json.gz
|
||||
git add packages/thirdweb/typedoc/documentation.json.gz
|
||||
git add snippets/feature_snippets_react.json
|
||||
git add snippets/feature_snippets_sdk.json
|
||||
git add snippets/snippets.json
|
||||
|
||||
@@ -1,47 +0,0 @@
|
||||
name: Release Next
|
||||
|
||||
on:
|
||||
push:
|
||||
paths:
|
||||
- ".changeset/**"
|
||||
- "packages/**"
|
||||
branches:
|
||||
- next
|
||||
|
||||
env:
|
||||
TURBO_TOKEN: ${{ secrets.TURBO_TOKEN }}
|
||||
TURBO_TEAM: ${{ secrets.TURBO_TEAM }}
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
|
||||
jobs:
|
||||
release:
|
||||
name: Release
|
||||
timeout-minutes: 30
|
||||
runs-on: ubuntu-latest-16
|
||||
steps:
|
||||
- name: Checkout branch
|
||||
uses: actions/checkout@v3
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Setup bun
|
||||
uses: oven-sh/setup-bun@v1
|
||||
with:
|
||||
bun-version: 1.0.21
|
||||
|
||||
- name: Install
|
||||
uses: ./.github/composite-actions/install
|
||||
|
||||
- name: Build
|
||||
run: pnpm build
|
||||
|
||||
- name: Create @next release
|
||||
run: |
|
||||
git checkout next
|
||||
pnpm version-packages:next
|
||||
pnpm release:next
|
||||
env:
|
||||
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
@@ -8,6 +8,7 @@ on:
|
||||
paths:
|
||||
- ".changeset/**"
|
||||
- "packages/**"
|
||||
- "legacy_packages/**"
|
||||
branches:
|
||||
- main
|
||||
|
||||
|
||||
@@ -19,7 +19,7 @@ jobs:
|
||||
|
||||
- name: Run chains sync
|
||||
run: bun run db:sync
|
||||
working-directory: ./packages/chains
|
||||
working-directory: ./legacy_packages/chains
|
||||
|
||||
- name: Check for Changes
|
||||
id: git-check
|
||||
|
||||
+2
-2
@@ -10,7 +10,7 @@ dist-ssr
|
||||
.cache
|
||||
server/dist
|
||||
public/dist
|
||||
./packages/contracts-js/abis
|
||||
./legacy_packages/contracts-js/abis
|
||||
.idea/
|
||||
.yalc/
|
||||
yalc.lock
|
||||
@@ -20,4 +20,4 @@ playwright-report/
|
||||
.env/
|
||||
|
||||
# Artifacts
|
||||
packages/cli/artifacts/
|
||||
legacy_packages/cli/artifacts/
|
||||
@@ -1,11 +1,11 @@
|
||||
<p align="center">
|
||||
<br />
|
||||
<a href="https://thirdweb.com">
|
||||
<img src="https://github.com/thirdweb-dev/js/blob/main/packages/sdk/logo.svg?raw=true" width="200" alt=""/></a>
|
||||
<img src="https://github.com/thirdweb-dev/js/blob/main/legacy_packages/sdk/logo.svg?raw=true" width="200" alt=""/></a>
|
||||
<br />
|
||||
</p>
|
||||
|
||||
<h1 align="center"><a href='https://thirdweb.com/'>thirdweb</a> JavaScript/TypeScript monorepo</h1>
|
||||
<h1 align="center"><a href='https://thirdweb.com/'>thirdweb</a> TypeScript SDK</h1>
|
||||
|
||||
<p align="center">
|
||||
<a href="https://github.com/thirdweb-dev/js/actions/workflows/build-test-lint.yml">
|
||||
@@ -16,38 +16,71 @@
|
||||
</a>
|
||||
</p>
|
||||
|
||||
<p align="center"><strong>Best in class web3 SDKs for Browser, Node and Mobile apps</strong></p>
|
||||
<p align="center"><strong>All-in-one web3 SDK for Browser, Node and Mobile apps</strong></p>
|
||||
|
||||
> [!IMPORTANT]
|
||||
> We rewrote the thirdweb SDK from scratch for performance! Head over to the [v5 SDK](https://github.com/thirdweb-dev/js/tree/main/packages/thirdweb).
|
||||
|
||||
## Features
|
||||
|
||||
- Support for React & React-Native
|
||||
- First party support for [Embedded Wallets](https://portal.thirdweb.com/connect/embedded-wallet/overview) (social/email login)
|
||||
- First party support for [Account Abstraction](https://portal.thirdweb.com/connect/account-abstraction)
|
||||
- Instant connection to any chain with RPC Edge integration
|
||||
- Integrated IPFS upload/download
|
||||
- UI Components for connection, transactions, nft rendering
|
||||
- High level contract extensions for interacting with common standards
|
||||
- Automatic ABI resolution
|
||||
|
||||
## Library Comparison
|
||||
|
||||
| | thirdweb | Wagmi | Viem | Ethers@6 |
|
||||
| ----------------------------------------- | -------- | ------------------ | ------------------ | -------- |
|
||||
| Type safe contract API | ✅ | ✅ | ✅ | ✅ |
|
||||
| Type safe wallet API | ✅ | ✅ | ✅ | ✅ |
|
||||
| EVM utils | ✅ | ❌ | ✅ | ✅ |
|
||||
| RPC for any EVM | ✅ | ⚠️ public RPC only | ⚠️ public RPC only | ❌ |
|
||||
| Automatic ABI Resolution | ✅ | ❌ | ❌ | ❌ |
|
||||
| IPFS Upload/Download | ✅ | ❌ | ❌ | ❌ |
|
||||
| Embedded wallet (email/ social login) | ✅ | ⚠️ via 3rd party | ❌ | ❌ |
|
||||
| Account abstraction (ERC4337) support | ✅ | ⚠️ via 3rd party | ⚠️ via 3rd party | ❌ |
|
||||
| Web3 wallet connectors | ✅ | ✅ | ❌ | ❌ |
|
||||
| Local wallet creation | ✅ | ❌ | ✅ | ✅ |
|
||||
| Auth (SIWE) | ✅ | ⚠️ via 3rd party | ❌ | ❌ |
|
||||
| Extensions functions for common standards | ✅ | ❌ | ❌ | ❌ |
|
||||
| React Hooks | ✅ | ✅ | ❌ | ❌ |
|
||||
| React UI components | ✅ | ❌ | ❌ | ❌ |
|
||||
| React Native Hooks | ✅ | ❌ | ❌ | ❌ |
|
||||
| React Native UI Components | ✅ | ❌ | ❌ | ❌ |
|
||||
|
||||
## Packages
|
||||
|
||||
| Package | Description | Latest Version |
|
||||
| ---------------------------------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||
| [/sdk](./packages/sdk) | Best in class web3 SDK for Browser, Node and Mobile apps | <a href="https://www.npmjs.com/package/@thirdweb-dev/sdk"><img src="https://img.shields.io/npm/v/@thirdweb-dev/sdk?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/wallets](./packages/wallets) | Unified web3 Wallet library to integrate any wallet into your applications. | <a href="https://www.npmjs.com/package/@thirdweb-dev/wallets"><img src="https://img.shields.io/npm/v/@thirdweb-dev/wallets?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/react](./packages/react) | Ultimate collection of React hooks for your web3 apps | <a href="https://www.npmjs.com/package/@thirdweb-dev/react"><img src="https://img.shields.io/npm/v/@thirdweb-dev/react?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/react-native](./packages/react-native) | Ultimate collection of React hooks for your native mobile web3 apps | <a href="https://www.npmjs.com/package/@thirdweb-dev/react-native"><img src="https://img.shields.io/npm/v/@thirdweb-dev/react-native?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/auth](./packages/auth) | Best in class wallet authentication for Node backends | <a href="https://www.npmjs.com/package/@thirdweb-dev/auth"><img src="https://img.shields.io/npm/v/@thirdweb-dev/auth?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/storage](./packages/storage) | Best in class decentralized storage SDK for Browser and Node | <a href="https://www.npmjs.com/package/@thirdweb-dev/storage"><img src="https://img.shields.io/npm/v/@thirdweb-dev/storage?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/cli](./packages/cli) | Publish and deploy smart contracts without dealing with private keys | <a href="https://www.npmjs.com/package/thirdweb"><img src="https://img.shields.io/npm/v/thirdweb?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
| [/chains](./packages/chains) | All EVM chain information as JS objects for easy handling | <a href="https://www.npmjs.com/package/@thirdweb-dev/chains"><img src="https://img.shields.io/npm/v/@thirdweb-dev/chains?color=red&label=npm&logo=npm" alt="npm version"/></a> |
|
||||
|
||||
## Documentation
|
||||
|
||||
Visit [https://portal.thirdweb.com/](https://portal.thirdweb.com/) to view the full documentation.
|
||||
|
||||
<br />
|
||||
| Package | Description |
|
||||
| ----------------------------------------------- | --------------------------------------------------------------------------- |
|
||||
| [/sdk](./legacy_packages/sdk) | Best in class web3 SDK for Browser, Node and Mobile apps |
|
||||
| [/wallets](./legacy_packages/wallets) | Unified web3 Wallet library to integrate any wallet into your applications. |
|
||||
| [/react](./legacy_packages/react) | Ultimate collection of React hooks for your web3 apps |
|
||||
| [/react-native](./legacy_packages/react-native) | Ultimate collection of React hooks for your native mobile web3 apps |
|
||||
| [/auth](./legacy_packages/auth) | Best in class wallet authentication for Node backends |
|
||||
| [/storage](./legacy_packages/storage) | Best in class decentralized storage SDK for Browser and Node |
|
||||
| [/cli](./legacy_packages/cli) | Publish and deploy smart contracts without dealing with private keys |
|
||||
| [/chains](./legacy_packages/chains) | All EVM chain information as JS objects for easy handling |
|
||||
|
||||
## Contributing
|
||||
|
||||
We welcome contributions from all developers, regardless of experience level. If you are interested in contributing, please read our [Contributing Guide](.github/contributing.md) where you'll learn how the repo works, how to test your changes, and how to submit a pull request.
|
||||
We welcome contributions from all developers regardless of experience level. If you are interested in contributing, please read our [Contributing Guide](.github/contributing.md) to learn how the repo works, how to test your changes, and how to submit a pull request.
|
||||
|
||||
<br />
|
||||
See our [open source page](https://thirdweb.com/open-source) for more information on our open-source bounties and program.
|
||||
|
||||
## Community
|
||||
## Additional Resources
|
||||
|
||||
The best place to discuss your ideas, ask questions, and troubleshoot issues is our [Discord server](https://discord.gg/thirdweb).
|
||||
- [SDK Documentation](https://portal.thirdweb.com/typescript/v5)
|
||||
- [Templates](https://thirdweb.com/templates)
|
||||
- [YouTube](https://www.youtube.com/c/thirdweb_)
|
||||
|
||||
<br/>
|
||||
## Support
|
||||
|
||||
For help or feedback, please [visit our support site](https://thirdweb.com/support)
|
||||
|
||||
## Security
|
||||
|
||||
|
||||
@@ -1,5 +1,98 @@
|
||||
# @thirdweb-dev/auth
|
||||
|
||||
## 4.1.49
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies [[`13f00cf`](https://github.com/thirdweb-dev/js/commit/13f00cf476b126683649a166e9e03b8e3f6599e4)]:
|
||||
- @thirdweb-dev/wallets@2.4.27
|
||||
|
||||
## 4.1.48
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies []:
|
||||
- @thirdweb-dev/wallets@2.4.26
|
||||
|
||||
## 4.1.47
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies []:
|
||||
- @thirdweb-dev/wallets@2.4.25
|
||||
|
||||
## 4.1.46
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies [[`79c9e13`](https://github.com/thirdweb-dev/js/commit/79c9e130fdc6e1f7de1486894a5ac3e6d6776fa4)]:
|
||||
- @thirdweb-dev/wallets@2.4.24
|
||||
|
||||
## 4.1.45
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies [[`802ba8c`](https://github.com/thirdweb-dev/js/commit/802ba8c5a980d3bddd308f9b3d14cc9cbb5453d5)]:
|
||||
- @thirdweb-dev/wallets@2.4.23
|
||||
|
||||
## 4.1.44
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies []:
|
||||
- @thirdweb-dev/wallets@2.4.22
|
||||
|
||||
## 4.1.43
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies []:
|
||||
- @thirdweb-dev/wallets@2.4.21
|
||||
|
||||
## 4.1.42
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies []:
|
||||
- @thirdweb-dev/wallets@2.4.20
|
||||
|
||||
## 4.1.41
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies []:
|
||||
- @thirdweb-dev/wallets@2.4.19
|
||||
|
||||
## 4.1.40
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies [[`cabfc29`](https://github.com/thirdweb-dev/js/commit/cabfc29119f25a78010f59f766bdcb8c392afa2d)]:
|
||||
- @thirdweb-dev/wallets@2.4.18
|
||||
|
||||
## 4.1.39
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies [[`c894270`](https://github.com/thirdweb-dev/js/commit/c894270401850575d1a4df73e16198177b46477a), [`332a145`](https://github.com/thirdweb-dev/js/commit/332a14552bf95e13e5220b1bd73414f000088568)]:
|
||||
- @thirdweb-dev/wallets@2.4.17
|
||||
|
||||
## 4.1.38
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- [#2417](https://github.com/thirdweb-dev/js/pull/2417) [`862905e`](https://github.com/thirdweb-dev/js/commit/862905e161a091c15eb9b054cfcca0e5d2879fd6) Thanks [@jnsdls](https://github.com/jnsdls)! - make verify login payload be self-sufficient
|
||||
|
||||
- Updated dependencies [[`862905e`](https://github.com/thirdweb-dev/js/commit/862905e161a091c15eb9b054cfcca0e5d2879fd6)]:
|
||||
- @thirdweb-dev/wallets@2.4.16
|
||||
|
||||
## 4.1.37
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- Updated dependencies [[`74a92dc`](https://github.com/thirdweb-dev/js/commit/74a92dcb7dc4be7d03bcb8b7211e87016f52a81f)]:
|
||||
- @thirdweb-dev/wallets@2.4.15
|
||||
|
||||
## 4.1.36
|
||||
|
||||
### Patch Changes
|
||||
@@ -1,6 +1,6 @@
|
||||
<p align="center">
|
||||
<br />
|
||||
<a href="https://thirdweb.com"><img src="https://github.com/thirdweb-dev/js/blob/main/packages/sdk/logo.svg?raw=true" width="200" alt=""/></a>
|
||||
<a href="https://thirdweb.com"><img src="https://github.com/thirdweb-dev/js/blob/main/legacy_packages/sdk/logo.svg?raw=true" width="200" alt=""/></a>
|
||||
<br />
|
||||
</p>
|
||||
<h1 align="center">thirdweb Auth</h1>
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@thirdweb-dev/auth",
|
||||
"version": "4.1.36",
|
||||
"version": "4.1.49",
|
||||
"main": "dist/thirdweb-dev-auth.cjs.js",
|
||||
"module": "dist/thirdweb-dev-auth.esm.js",
|
||||
"browser": {
|
||||
@@ -51,7 +51,7 @@
|
||||
},
|
||||
"./package.json": "./package.json"
|
||||
},
|
||||
"repository": "https://github.com/thirdweb-dev/js/tree/main/packages/auth",
|
||||
"repository": "https://github.com/thirdweb-dev/js/tree/main/legacy_packages/auth",
|
||||
"author": "thirdweb eng <[email protected]>",
|
||||
"license": "Apache-2.0",
|
||||
"sideEffects": false,
|
||||
@@ -61,7 +61,7 @@
|
||||
"lint": "eslint src/ && bunx publint --strict --level warning",
|
||||
"fix": "eslint src/ --fix",
|
||||
"clean": "rm -rf dist/ && rm -rf node_modules/",
|
||||
"test": "mocha --config './test/.mocharc.json' --timeout 30000 --parallel './test/**/*.test.ts'",
|
||||
"test": "mocha --config './test/.mocharc.json' --timeout 240000 --parallel './test/**/*.test.ts'",
|
||||
"push": "yalc push"
|
||||
},
|
||||
"preconstruct": {
|
||||
@@ -96,12 +96,9 @@
|
||||
"@types/express": "^4.17.13",
|
||||
"@types/mocha": "^10.0.0",
|
||||
"@types/uuid": "^9.0.5",
|
||||
"@typescript-eslint/eslint-plugin": "^6.2.0",
|
||||
"@typescript-eslint/parser": "^6.19.1",
|
||||
"chai": "^4.3.6",
|
||||
"cookie-parser": "^1.4.6",
|
||||
"eslint": "^8.56.0",
|
||||
"eslint-config-prettier": "^8.9.0",
|
||||
"eslint-config-thirdweb": "workspace:*",
|
||||
"eslint-plugin-import": "^2.26.0",
|
||||
"eslint-plugin-inclusive-language": "^2.2.0",
|
||||
@@ -110,10 +107,9 @@
|
||||
"ethers": "^5.7.2",
|
||||
"express": "^4.18.1",
|
||||
"fastify": "^4.25.2",
|
||||
"mocha": "^10.2.0",
|
||||
"mocha": "10.4.0",
|
||||
"next": "^13.4",
|
||||
"next-auth": "^4.22.3",
|
||||
"prettier": "^3.1.1",
|
||||
"typescript": "^5.3.3"
|
||||
},
|
||||
"peerDependencies": {
|
||||
@@ -23,14 +23,21 @@ import {
|
||||
AuthenticateOptionsWithOptionalDomain,
|
||||
AuthenticationPayload,
|
||||
} from "./schema/authenticate";
|
||||
import { ThirdwebAuthOptions } from "./types";
|
||||
|
||||
export class ThirdwebAuth {
|
||||
private domain: string;
|
||||
private wallet: GenericAuthWallet;
|
||||
private options: ThirdwebAuthOptions;
|
||||
|
||||
constructor(wallet: GenericAuthWallet, domain: string) {
|
||||
constructor(
|
||||
wallet: GenericAuthWallet,
|
||||
domain: string,
|
||||
options: ThirdwebAuthOptions = {},
|
||||
) {
|
||||
this.wallet = wallet;
|
||||
this.domain = domain;
|
||||
this.options = options;
|
||||
}
|
||||
|
||||
public updateWallet(wallet: GenericAuthWallet) {
|
||||
@@ -66,9 +73,9 @@ export class ThirdwebAuth {
|
||||
options?: VerifyOptionsWithOptionalDomain,
|
||||
): Promise<string> {
|
||||
return verifyLoginPayload({
|
||||
wallet: this.wallet,
|
||||
payload,
|
||||
options: this.formatOptions(options),
|
||||
clientOptions: this.options,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -80,6 +87,7 @@ export class ThirdwebAuth {
|
||||
wallet: this.wallet,
|
||||
payload,
|
||||
options: this.formatOptions(options),
|
||||
clientOptions: this.options,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -99,6 +107,7 @@ export class ThirdwebAuth {
|
||||
wallet: this.wallet,
|
||||
jwt,
|
||||
options: this.formatOptions(options),
|
||||
clientOptions: this.options,
|
||||
});
|
||||
}
|
||||
|
||||
+7
-2
@@ -14,6 +14,7 @@ import {
|
||||
import { GenerateOptionsSchema } from "../schema/generate";
|
||||
import { RefreshOptionsSchema } from "../schema/refresh";
|
||||
import { verifyLoginPayload } from "./login";
|
||||
import { verifySignature } from "./verify-signature";
|
||||
|
||||
function isBrowser() {
|
||||
return typeof window !== "undefined";
|
||||
@@ -71,15 +72,16 @@ export async function generateJWT({
|
||||
wallet,
|
||||
payload,
|
||||
options,
|
||||
clientOptions,
|
||||
}: GenerateJwtParams): Promise<string> {
|
||||
const parsedOptions = GenerateOptionsSchema.parse(options);
|
||||
const userAddress = await verifyLoginPayload({
|
||||
wallet,
|
||||
payload,
|
||||
options: {
|
||||
domain: parsedOptions.domain,
|
||||
...parsedOptions.verifyOptions,
|
||||
},
|
||||
clientOptions,
|
||||
});
|
||||
|
||||
let session: Json | undefined = undefined;
|
||||
@@ -156,6 +158,7 @@ export async function authenticateJWT<TSession extends Json = Json>({
|
||||
wallet,
|
||||
jwt,
|
||||
options,
|
||||
clientOptions,
|
||||
}: AuthenticateJwtParams): Promise<User<TSession>> {
|
||||
const parsedOptions = AuthenticateOptionsSchema.parse(options);
|
||||
const { payload, signature } = parseJWT(jwt);
|
||||
@@ -210,11 +213,13 @@ export async function authenticateJWT<TSession extends Json = Json>({
|
||||
}
|
||||
}
|
||||
|
||||
const verified = await wallet.verifySignature(
|
||||
const verified = await verifySignature(
|
||||
JSON.stringify(payload),
|
||||
signature,
|
||||
issuerAddress,
|
||||
chainId,
|
||||
clientOptions.clientId,
|
||||
clientOptions.secretKey,
|
||||
);
|
||||
if (!verified) {
|
||||
throw new Error(
|
||||
+10
-12
@@ -10,6 +10,7 @@ import {
|
||||
LoginPayloadDataSchema,
|
||||
} from "../schema/login";
|
||||
import { VerifyOptionsSchema } from "../schema/verify";
|
||||
import { verifySignature } from "./verify-signature";
|
||||
|
||||
/**
|
||||
* Create an EIP-4361 & CAIP-122 compliant message to sign based on the login payload
|
||||
@@ -113,18 +114,12 @@ export async function buildAndSignLoginPayload({
|
||||
}
|
||||
|
||||
export async function verifyLoginPayload({
|
||||
wallet,
|
||||
payload,
|
||||
options,
|
||||
clientOptions,
|
||||
}: VerifyLoginPayloadParams): Promise<string> {
|
||||
const parsedOptions = VerifyOptionsSchema.parse(options);
|
||||
|
||||
if (payload.payload.type !== wallet.type) {
|
||||
throw new Error(
|
||||
`Expected chain type '${wallet.type}' does not match chain type on payload '${payload.payload.type}'`,
|
||||
);
|
||||
}
|
||||
|
||||
// Check that the intended domain matches the domain of the payload
|
||||
if (payload.payload.domain !== parsedOptions.domain) {
|
||||
throw new Error(
|
||||
@@ -204,16 +199,19 @@ export async function verifyLoginPayload({
|
||||
|
||||
// Check that the signing address is the claimed wallet address
|
||||
const message = createLoginMessage(payload.payload);
|
||||
const chainId =
|
||||
wallet.type === "evm" && payload.payload.chain_id
|
||||
? parseInt(payload.payload.chain_id)
|
||||
: undefined;
|
||||
const verified = await wallet.verifySignature(
|
||||
const chainId = payload.payload.chain_id
|
||||
? parseInt(payload.payload.chain_id)
|
||||
: undefined;
|
||||
|
||||
const verified = await verifySignature(
|
||||
message,
|
||||
payload.signature,
|
||||
payload.payload.address,
|
||||
chainId,
|
||||
clientOptions?.clientId,
|
||||
clientOptions?.secretKey,
|
||||
);
|
||||
|
||||
if (!verified) {
|
||||
throw new Error(
|
||||
`Signer address does not match payload address '${payload.payload.address.toLowerCase()}'`,
|
||||
@@ -0,0 +1,35 @@
|
||||
import { checkContractWalletSignature } from "@thirdweb-dev/wallets";
|
||||
import { utils } from "ethers";
|
||||
|
||||
export async function verifySignature(
|
||||
message: string,
|
||||
signature: string,
|
||||
address: string,
|
||||
chainId?: number,
|
||||
clientId?: string,
|
||||
secretKey?: string,
|
||||
): Promise<boolean> {
|
||||
try {
|
||||
const messageHash = utils.hashMessage(message);
|
||||
const messageHashBytes = utils.arrayify(messageHash);
|
||||
const recoveredAddress = utils.recoverAddress(messageHashBytes, signature);
|
||||
|
||||
if (recoveredAddress === address) {
|
||||
return true;
|
||||
}
|
||||
} catch {
|
||||
// no-op
|
||||
}
|
||||
|
||||
if (!chainId) {
|
||||
return false;
|
||||
}
|
||||
return checkContractWalletSignature(
|
||||
message,
|
||||
signature,
|
||||
address,
|
||||
chainId,
|
||||
clientId,
|
||||
secretKey,
|
||||
);
|
||||
}
|
||||
+4
-1
@@ -7,6 +7,7 @@ import {
|
||||
} from "./authenticate";
|
||||
import { RefreshOptions } from "./refresh";
|
||||
import { GenerateOptions } from "./generate";
|
||||
import { ThirdwebAuthOptions } from "../types";
|
||||
|
||||
export type BuildLoginPayloadParams = {
|
||||
wallet: GenericAuthWallet;
|
||||
@@ -19,9 +20,9 @@ export type SignLoginPayloadParams = {
|
||||
};
|
||||
|
||||
export type VerifyLoginPayloadParams = {
|
||||
wallet: GenericAuthWallet;
|
||||
payload: LoginPayload;
|
||||
options: VerifyOptions;
|
||||
clientOptions: ThirdwebAuthOptions;
|
||||
};
|
||||
|
||||
export type BuildJwtParams = {
|
||||
@@ -33,6 +34,7 @@ export type GenerateJwtParams = {
|
||||
wallet: GenericAuthWallet;
|
||||
payload: LoginPayload;
|
||||
options: GenerateOptions;
|
||||
clientOptions: ThirdwebAuthOptions;
|
||||
};
|
||||
|
||||
export type RefreshJwtParams = {
|
||||
@@ -45,4 +47,5 @@ export type AuthenticateJwtParams = {
|
||||
wallet: GenericAuthWallet;
|
||||
jwt: string;
|
||||
options: AuthenticateOptions;
|
||||
clientOptions: ThirdwebAuthOptions;
|
||||
};
|
||||
@@ -0,0 +1,4 @@
|
||||
export type ThirdwebAuthOptions = {
|
||||
clientId?: string;
|
||||
secretKey?: string;
|
||||
};
|
||||
@@ -41,7 +41,7 @@ export function ThirdwebAuth<
|
||||
): ThirdwebAuthReturnType<TData, TSession> {
|
||||
const ctx = {
|
||||
...cfg,
|
||||
auth: new ThirdwebAuthSDK(cfg.wallet, cfg.domain),
|
||||
auth: new ThirdwebAuthSDK(cfg.wallet, cfg.domain, cfg.thirdwebAuthOptions),
|
||||
};
|
||||
|
||||
const router = express.Router();
|
||||
+2
@@ -1,4 +1,5 @@
|
||||
import { ThirdwebAuth } from "../../core";
|
||||
import { ThirdwebAuthOptions } from "../../core/types";
|
||||
import { Json, LoginPayloadOutputSchema, User } from "../../core";
|
||||
import type { GenericAuthWallet } from "@thirdweb-dev/wallets";
|
||||
import { Request } from "express";
|
||||
@@ -68,6 +69,7 @@ export type ThirdwebAuthConfig<
|
||||
| ((user: User, req: Request) => void)
|
||||
| ((user: User, req: Request) => Promise<void>);
|
||||
};
|
||||
thirdwebAuthOptions?: ThirdwebAuthOptions;
|
||||
};
|
||||
|
||||
export type ThirdwebAuthContext<
|
||||
@@ -44,7 +44,7 @@ export function ThirdwebAuth<
|
||||
): ThirdwebAuthReturnType<TData, TSession> {
|
||||
const ctx = {
|
||||
...cfg,
|
||||
auth: new ThirdwebAuthSDK(cfg.wallet, cfg.domain),
|
||||
auth: new ThirdwebAuthSDK(cfg.wallet, cfg.domain, cfg.thirdwebAuthOptions),
|
||||
};
|
||||
|
||||
const authRouter = async (
|
||||
+2
@@ -9,6 +9,7 @@ import {
|
||||
import { z } from "zod";
|
||||
import { IncomingMessage, ServerResponse } from "http";
|
||||
import { ZodTypeProvider } from "fastify-type-provider-zod";
|
||||
import { ThirdwebAuthOptions } from "../../core/types";
|
||||
|
||||
export const PayloadBodySchema = z.object({
|
||||
address: z.string(),
|
||||
@@ -76,6 +77,7 @@ export type ThirdwebAuthConfig<
|
||||
| ((user: User, req: FastifyRequest) => void)
|
||||
| ((user: User, req: FastifyRequest) => Promise<void>);
|
||||
};
|
||||
thirdwebAuthOptions?: ThirdwebAuthOptions;
|
||||
};
|
||||
|
||||
export type ThirdwebAuthContext<
|
||||
Vendored
+3
-1
@@ -2,6 +2,7 @@ import type { GenericAuthWallet } from "@thirdweb-dev/wallets";
|
||||
import { z } from "zod";
|
||||
|
||||
import { Json, LoginPayloadOutputSchema, User } from "../../core";
|
||||
import { ThirdwebAuthOptions } from "../../core/types";
|
||||
|
||||
export const PayloadBodySchema = z.object({
|
||||
address: z.string(),
|
||||
@@ -55,8 +56,9 @@ export type ThirdwebAuthConfigShared = {
|
||||
sameSite?: "lax" | "strict" | "none";
|
||||
secure?: boolean;
|
||||
};
|
||||
thirdwebAuthOptions?: ThirdwebAuthOptions;
|
||||
};
|
||||
|
||||
export type ThirdwebNextContext = {
|
||||
params?: Record<string, string | string[]>
|
||||
params?: Record<string, string | string[]>;
|
||||
};
|
||||
+9
-15
@@ -8,19 +8,10 @@ import loginHandler from "./routes/login";
|
||||
import logoutHandler from "./routes/logout";
|
||||
import userHandler from "./routes/user";
|
||||
import switchAccountHandler from "./routes/switch-account";
|
||||
import type {
|
||||
ThirdwebAuthConfig,
|
||||
ThirdwebAuthContext,
|
||||
} from "./types";
|
||||
import type {
|
||||
ThirdwebAuthRoute,
|
||||
ThirdwebNextContext,
|
||||
} from "../common/types";
|
||||
import type { ThirdwebAuthConfig, ThirdwebAuthContext } from "./types";
|
||||
import type { ThirdwebAuthRoute, ThirdwebNextContext } from "../common/types";
|
||||
|
||||
export type {
|
||||
ThirdwebAuthConfig,
|
||||
ThirdwebAuthContext,
|
||||
} from "./types";
|
||||
export type { ThirdwebAuthConfig, ThirdwebAuthContext } from "./types";
|
||||
|
||||
export async function ThirdwebAuthRouter(
|
||||
req: NextRequest,
|
||||
@@ -44,7 +35,7 @@ export async function ThirdwebAuthRouter(
|
||||
default:
|
||||
return Response.json(
|
||||
{ message: "Invalid route for authentication." },
|
||||
{ status: 400},
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -55,10 +46,13 @@ export function ThirdwebAuth<
|
||||
>(cfg: ThirdwebAuthConfig<TData, TSession>) {
|
||||
const authCtx = {
|
||||
...cfg,
|
||||
auth: new ThirdwebAuthSDK(cfg.wallet, cfg.domain),
|
||||
auth: new ThirdwebAuthSDK(cfg.wallet, cfg.domain, cfg.thirdwebAuthOptions),
|
||||
};
|
||||
|
||||
async function ThirdwebAuthHandler(req: NextRequest, ctx: ThirdwebNextContext) {
|
||||
async function ThirdwebAuthHandler(
|
||||
req: NextRequest,
|
||||
ctx: ThirdwebNextContext,
|
||||
) {
|
||||
return await ThirdwebAuthRouter(req, ctx, authCtx as ThirdwebAuthContext);
|
||||
}
|
||||
|
||||
+1
-1
@@ -52,7 +52,7 @@ export function ThirdwebAuth<
|
||||
>(cfg: ThirdwebAuthConfig<TData, TSession>) {
|
||||
const ctx = {
|
||||
...cfg,
|
||||
auth: new ThirdwebAuthSDK(cfg.wallet, cfg.domain),
|
||||
auth: new ThirdwebAuthSDK(cfg.wallet, cfg.domain, cfg.thirdwebAuthOptions),
|
||||
};
|
||||
|
||||
function ThirdwebAuthHandler(
|
||||
@@ -3,6 +3,8 @@ import { EthersWallet } from "@thirdweb-dev/wallets/evm/wallets/ethers";
|
||||
import { expect } from "chai";
|
||||
import { Wallet } from "ethers";
|
||||
|
||||
require("dotenv-mono").load();
|
||||
|
||||
describe("Wallet Authentication - EVM", async () => {
|
||||
let adminWallet: any, signerWallet: any, attackerWallet: any;
|
||||
let auth: ThirdwebAuth;
|
||||
@@ -18,7 +20,9 @@ describe("Wallet Authentication - EVM", async () => {
|
||||
signerWallet = new EthersWallet(signerSigner);
|
||||
attackerWallet = new EthersWallet(attackerSigner);
|
||||
|
||||
auth = new ThirdwebAuth(signerWallet, "thirdweb.com");
|
||||
auth = new ThirdwebAuth(signerWallet, "thirdweb.com", {
|
||||
secretKey: process.env.TW_SECRET_KEY,
|
||||
});
|
||||
});
|
||||
|
||||
beforeEach(async () => {
|
||||
@@ -0,0 +1,384 @@
|
||||
import { LocalWallet, SmartWallet } from "@thirdweb-dev/wallets";
|
||||
import { ThirdwebAuth } from "../src/core";
|
||||
import { EthersWallet } from "@thirdweb-dev/wallets/evm/wallets/ethers";
|
||||
import { expect } from "chai";
|
||||
import { Wallet } from "ethers";
|
||||
|
||||
require("dotenv-mono").load();
|
||||
|
||||
describe("Wallet Authentication - EVM - Smart Wallet", async () => {
|
||||
let adminWallet: any, signerWallet: any, attackerWallet: any;
|
||||
let auth: ThirdwebAuth;
|
||||
|
||||
before(async () => {
|
||||
const factoryAddress = "0xbf1C9aA4B1A085f7DA890a44E82B0A1289A40052";
|
||||
const chain = 421614;
|
||||
const localWallet = new LocalWallet();
|
||||
await localWallet.generate();
|
||||
const smartWallet = new SmartWallet({
|
||||
chain: chain,
|
||||
factoryAddress: factoryAddress,
|
||||
gasless: true,
|
||||
secretKey: process.env.TW_SECRET_KEY,
|
||||
});
|
||||
await smartWallet.connect({ personalWallet: localWallet });
|
||||
|
||||
adminWallet = new EthersWallet(Wallet.createRandom());
|
||||
signerWallet = smartWallet;
|
||||
attackerWallet = new EthersWallet(Wallet.createRandom());
|
||||
|
||||
auth = new ThirdwebAuth(signerWallet, "thirdweb.com", {
|
||||
secretKey: process.env.TW_SECRET_KEY,
|
||||
});
|
||||
});
|
||||
|
||||
beforeEach(async () => {
|
||||
auth.updateWallet(signerWallet);
|
||||
});
|
||||
|
||||
it("Should verify logged in wallet", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const address = await auth.verify(payload);
|
||||
|
||||
expect(address).to.equal(await signerWallet.getAddress());
|
||||
});
|
||||
|
||||
it("Should verify logged in wallet with chain ID and expiration", async () => {
|
||||
const payload = await auth.login({
|
||||
expirationTime: new Date(Date.now() + 1000 * 60 * 5),
|
||||
chainId: "421614",
|
||||
});
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const address = await auth.verify(payload, {
|
||||
chainId: "421614",
|
||||
});
|
||||
|
||||
expect(address).to.equal(await signerWallet.getAddress());
|
||||
});
|
||||
|
||||
it("Should verify payload with resources", async () => {
|
||||
const payload = await auth.login({
|
||||
resources: ["https://example.com", "https://test.com"],
|
||||
});
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const address = await auth.verify(payload, {
|
||||
resources: ["https://example.com", "https://test.com"],
|
||||
});
|
||||
|
||||
expect(address).to.equal(await signerWallet.getAddress());
|
||||
});
|
||||
|
||||
it("Should reject payload without necessary resources", async () => {
|
||||
const payload = await auth.login({
|
||||
resources: ["https://example.com"],
|
||||
});
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
try {
|
||||
await auth.verify(payload, {
|
||||
resources: ["https://example.com", "https://test.com"],
|
||||
});
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.equal(
|
||||
"Login request is missing required resources: https://test.com",
|
||||
);
|
||||
}
|
||||
});
|
||||
|
||||
it("Should verify payload with customized statement", async () => {
|
||||
const payload = await auth.login({
|
||||
statement: "Please sign!",
|
||||
});
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const address = await auth.verify(payload, {
|
||||
statement: "Please sign!",
|
||||
});
|
||||
|
||||
expect(address).to.equal(await signerWallet.getAddress());
|
||||
});
|
||||
|
||||
it("Should reject payload with incorrect statement", async () => {
|
||||
const payload = await auth.login({
|
||||
statement: "Please sign!",
|
||||
});
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
try {
|
||||
await auth.verify(payload, {
|
||||
statement: "Please sign again!",
|
||||
});
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.include(
|
||||
"Expected statement 'Please sign again!' does not match statement on payload",
|
||||
);
|
||||
}
|
||||
});
|
||||
|
||||
it("Should reject invalid nonce", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
try {
|
||||
await auth.verify(payload, {
|
||||
validateNonce: (nonce: string) => {
|
||||
if (nonce === payload.payload.nonce) {
|
||||
throw new Error();
|
||||
}
|
||||
},
|
||||
});
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.equal("Login request nonce is invalid");
|
||||
}
|
||||
});
|
||||
|
||||
it("Should accept valid nonce", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const address = await auth.verify(payload, {
|
||||
validateNonce: (nonce: string) => {
|
||||
if (nonce !== payload.payload.nonce) {
|
||||
throw new Error();
|
||||
}
|
||||
},
|
||||
});
|
||||
|
||||
expect(address).to.equal(await signerWallet.getAddress());
|
||||
});
|
||||
|
||||
it("Should reject payload with incorrect domain", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
try {
|
||||
await auth.verify(payload, { domain: "test.thirdweb.com" });
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.equal(
|
||||
"Expected domain 'test.thirdweb.com' does not match domain on payload 'thirdweb.com'",
|
||||
);
|
||||
}
|
||||
});
|
||||
|
||||
it("Should reject expired login payload", async () => {
|
||||
const payload = await auth.login({
|
||||
expirationTime: new Date(Date.now() - 1000 * 60 * 5),
|
||||
});
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
try {
|
||||
await auth.verify(payload);
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.equal("Login request has expired");
|
||||
}
|
||||
});
|
||||
|
||||
it("Should reject payload with incorrect chain ID", async () => {
|
||||
const payload = await auth.login({
|
||||
chainId: "1",
|
||||
});
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
try {
|
||||
await auth.verify(payload, {
|
||||
chainId: "137",
|
||||
});
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.equal(
|
||||
"Expected chain ID '137' does not match chain ID on payload '1'",
|
||||
);
|
||||
}
|
||||
});
|
||||
|
||||
it("Should reject payload with incorrect signer", async () => {
|
||||
const payload = await auth.login();
|
||||
payload.payload.address = await attackerWallet.getAddress();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
try {
|
||||
await auth.verify(payload);
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.contain("does not match payload address");
|
||||
}
|
||||
});
|
||||
|
||||
it("Should generate valid authentication token", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload);
|
||||
const user = await auth.authenticate(token);
|
||||
|
||||
expect(user.address).to.equal(await signerWallet.getAddress());
|
||||
});
|
||||
|
||||
it("Should reject token with incorrect domain", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload);
|
||||
|
||||
try {
|
||||
await auth.authenticate(token, { domain: "test.thirdweb.com" });
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.contain(
|
||||
"Expected token to be for the domain 'test.thirdweb.com', but found token with domain 'thirdweb.com'",
|
||||
);
|
||||
}
|
||||
});
|
||||
|
||||
it("Should reject token before invalid before", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload, {
|
||||
invalidBefore: new Date(Date.now() + 1000 * 60 * 5),
|
||||
});
|
||||
|
||||
try {
|
||||
await auth.authenticate(token);
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.contain("This token is invalid before");
|
||||
}
|
||||
});
|
||||
|
||||
it("Should reject expired authentication token", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload, {
|
||||
expirationTime: new Date(Date.now() - 1000 * 60 * 5),
|
||||
});
|
||||
|
||||
try {
|
||||
await auth.authenticate(token);
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.contain("This token expired");
|
||||
}
|
||||
});
|
||||
|
||||
it("Should reject if admin address is not connected wallet address", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload);
|
||||
|
||||
auth.updateWallet(signerWallet);
|
||||
try {
|
||||
await auth.authenticate(token);
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.contain(
|
||||
`The expected issuer address '${await signerWallet.getAddress()}' did not match the token issuer address '${await adminWallet.getAddress()}'`,
|
||||
);
|
||||
}
|
||||
});
|
||||
|
||||
it("Should accept token with valid token ID", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload, {
|
||||
tokenId: "test",
|
||||
});
|
||||
|
||||
const user = await auth.authenticate(token, {
|
||||
validateTokenId: (tokenId: string) => {
|
||||
if (tokenId !== "test") {
|
||||
throw new Error();
|
||||
}
|
||||
},
|
||||
});
|
||||
|
||||
expect(user.address).to.equal(await signerWallet.getAddress());
|
||||
});
|
||||
|
||||
it("Should reject token with invalid token ID", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload, {
|
||||
tokenId: "test",
|
||||
});
|
||||
|
||||
try {
|
||||
await auth.authenticate(token, {
|
||||
validateTokenId: (tokenId: string) => {
|
||||
if (tokenId !== "invalid") {
|
||||
throw new Error();
|
||||
}
|
||||
},
|
||||
});
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.contain("Token ID is invalid");
|
||||
}
|
||||
});
|
||||
|
||||
it("Should propagate session on token", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload, {
|
||||
session: { role: "admin" },
|
||||
});
|
||||
|
||||
const user = await auth.authenticate(token);
|
||||
|
||||
expect(user.address).to.equal(await signerWallet.getAddress());
|
||||
expect(user.session).to.deep.equal({ role: "admin" });
|
||||
});
|
||||
|
||||
it("Should call session callback function", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload, {
|
||||
session: (address: string) => {
|
||||
return { address, role: "admin" };
|
||||
},
|
||||
});
|
||||
|
||||
const user = await auth.authenticate(token);
|
||||
|
||||
expect(user.address).to.equal(await signerWallet.getAddress());
|
||||
expect(user.session).to.deep.equal({
|
||||
address: await signerWallet.getAddress(),
|
||||
role: "admin",
|
||||
});
|
||||
});
|
||||
|
||||
it("Should authenticate with issuer address", async () => {
|
||||
const payload = await auth.login();
|
||||
|
||||
auth.updateWallet(adminWallet);
|
||||
const token = await auth.generate(payload);
|
||||
|
||||
auth.updateWallet(attackerWallet);
|
||||
try {
|
||||
await auth.authenticate(token);
|
||||
expect.fail();
|
||||
} catch (err: any) {
|
||||
expect(err.message).to.contain("The expected issuer address");
|
||||
}
|
||||
|
||||
const user = await auth.authenticate(token, {
|
||||
issuerAddress: await adminWallet.getAddress(),
|
||||
});
|
||||
expect(user.address).to.equal(await signerWallet.getAddress());
|
||||
});
|
||||
});
|
||||
@@ -1,5 +1,49 @@
|
||||
# @thirdweb-dev/chains
|
||||
|
||||
## 0.1.83
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- [#2559](https://github.com/thirdweb-dev/js/pull/2559) [`095d227`](https://github.com/thirdweb-dev/js/commit/095d227a13d0c9c1de76fa3812b7f71b2130d532) Thanks [@github-actions](https://github.com/apps/github-actions)! - Synced Chains Package
|
||||
|
||||
## 0.1.82
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- [#2527](https://github.com/thirdweb-dev/js/pull/2527) [`cb0ef6a`](https://github.com/thirdweb-dev/js/commit/cb0ef6a6a25cee255e18b8489fdb4123bb69c279) Thanks [@github-actions](https://github.com/apps/github-actions)! - Synced Chains Package
|
||||
|
||||
## 0.1.81
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- [#2496](https://github.com/thirdweb-dev/js/pull/2496) [`863049d`](https://github.com/thirdweb-dev/js/commit/863049dc0ca989d2654b4aacba811263931a33fe) Thanks [@jnsdls](https://github.com/jnsdls)! - do not append `?bundleId` query param to rpc url if the bundle id is undefined
|
||||
|
||||
- [#2427](https://github.com/thirdweb-dev/js/pull/2427) [`8a20aa5`](https://github.com/thirdweb-dev/js/commit/8a20aa58259edc5bac578dc5e4f4d971ed7adf36) Thanks [@github-actions](https://github.com/apps/github-actions)! - Synced Chains Package
|
||||
|
||||
## 0.1.80
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- [#2484](https://github.com/thirdweb-dev/js/pull/2484) [`c494db8`](https://github.com/thirdweb-dev/js/commit/c494db87cbfa4b6fc4013abb01936e86a4350ea8) Thanks [@joaquim-verges](https://github.com/joaquim-verges)! - Update chains
|
||||
|
||||
## 0.1.79
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- [#2464](https://github.com/thirdweb-dev/js/pull/2464) [`2e01627`](https://github.com/thirdweb-dev/js/commit/2e01627c998a49a1dd41041f3743a28488c92697) Thanks [@joaquim-verges](https://github.com/joaquim-verges)! - Sync chains
|
||||
|
||||
## 0.1.78
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- [#2416](https://github.com/thirdweb-dev/js/pull/2416) [`588897d`](https://github.com/thirdweb-dev/js/commit/588897d1b04e6c63da13639aeb47ca701308e1b2) Thanks [@github-actions](https://github.com/apps/github-actions)! - Synced Chains Package
|
||||
|
||||
## 0.1.77
|
||||
|
||||
### Patch Changes
|
||||
|
||||
- [#2406](https://github.com/thirdweb-dev/js/pull/2406) [`047fbe2`](https://github.com/thirdweb-dev/js/commit/047fbe2918808cbc8fded90104458b6e38d1207d) Thanks [@github-actions](https://github.com/apps/github-actions)! - Synced Chains Package
|
||||
|
||||
## 0.1.76
|
||||
|
||||
### Patch Changes
|
||||
@@ -1,6 +1,6 @@
|
||||
<p align="center">
|
||||
<br />
|
||||
<a href="https://thirdweb.com"><img src="https://github.com/thirdweb-dev/js/blob/main/packages/sdk/logo.svg?raw=true" width="200" alt=""/></a>
|
||||
<a href="https://thirdweb.com"><img src="https://github.com/thirdweb-dev/js/blob/main/legacy_packages/sdk/logo.svg?raw=true" width="200" alt=""/></a>
|
||||
<br />
|
||||
</p>
|
||||
<h1 align="center">thirdweb chains</h1>
|
||||
@@ -71,7 +71,9 @@ export default {
|
||||
"wss://mainnet.gateway.tenderly.co",
|
||||
"https://rpc.blocknative.com/boost",
|
||||
"https://rpc.flashbots.net/fast",
|
||||
"https://rpc.mevblocker.io/fullprivacy"
|
||||
"https://rpc.mevblocker.io/fullprivacy",
|
||||
"https://eth.drpc.org",
|
||||
"wss://eth.drpc.org"
|
||||
],
|
||||
"shortName": "eth",
|
||||
"slip44": 60,
|
||||
@@ -57,7 +57,9 @@ export default {
|
||||
"https://optimism.gateway.tenderly.co",
|
||||
"wss://optimism.gateway.tenderly.co",
|
||||
"https://optimism-rpc.publicnode.com",
|
||||
"wss://optimism-rpc.publicnode.com"
|
||||
"wss://optimism-rpc.publicnode.com",
|
||||
"https://optimism.drpc.org",
|
||||
"wss://optimism.drpc.org"
|
||||
],
|
||||
"shortName": "oeth",
|
||||
"slug": "optimism",
|
||||
@@ -24,7 +24,9 @@ export default {
|
||||
"redFlags": [],
|
||||
"rpc": [
|
||||
"https://1001.rpc.thirdweb.com/${THIRDWEB_API_KEY}",
|
||||
"https://api.baobab.klaytn.net:8651"
|
||||
"https://api.baobab.klaytn.net:8651",
|
||||
"https://klaytn-baobab.drpc.org",
|
||||
"wss://klaytn-baobab.drpc.org"
|
||||
],
|
||||
"shortName": "Baobab",
|
||||
"slip44": 1,
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user