bloom_auth_server 0.3.0
bloom_auth_server: ^0.3.0 copied to clipboard
Server-side authentication primitives for the Bloom framework, including password hashing, session/bearer token issuance, rate limiting, password reset workflows, and auth middleware.
0.3.0 - 2026-08-25 #
Added #
- OAuth2 / social login. New
BloomOAuthProviderinterface with real Google and GitHub Authorization Code flow implementations (GoogleOAuthProvider,GitHubOAuthProvider) — authorization URL construction, code exchange, and profile fetch (GitHub's primary-verified-email lookup included).BloomOAuthFlowties a provider to the existing JWT session-token issuance via an app-suppliedresolveUsercallback, and includes a CSRF-safestategenerator. Closes the previous local-password-only auth gap.
0.2.0 - 2026-08-23 #
Breaking #
- Now depends on
bloom_serverinstead ofbloom_framework. Imports change frompackage:bloom_framework/bloom_server.darttopackage:bloom_server/bloom_server.dart. - No longer requires Flutter. The package now resolves against the Flutter-free
bloom_servercore, so it can be used from a plaindart run/dart compilebackend.
0.1.0 #
- Initial release of
bloom_auth_server. - Password Hashing & Verification: Strong, constant-time BCrypt hashing (
hashPassword,verifyPassword,dummyVerifyPassword) with configurable cost factor and user-enumeration defense. - Session & Bearer Token Issuance: Cryptographically signed Bearer JWT issuance (
issueSessionToken,verifySessionToken) bound with expiration, user identity, and custom claims. - Sliding-Window Rate Limiting & Account Lockout: In-memory rate limiting (
InMemoryRateLimiter) and persistent-style lockout tracker (InMemoryLockoutManager,AuthRateLimiter) with fail-closed security semantics. - Password Reset Workflows: Single-purpose, time-limited, HMAC-signed password reset tokens (
generatePasswordResetToken,verifyPasswordResetToken) cryptographically bound to the user's current password hash to ensure instant invalidation upon password modification. - Bloom Server Middleware: Drop-in
BloomAuthMiddlewareforBloomApiRoutersupporting Bearer token extraction, claim hydration, role validation, andBloomRequestcontext extensions (request.auth,request.authUserId,request.isAuthenticated).