Skip to content

Commit e7f95a8

Browse files
committed
Squashed commit of the following:
commit f057eff Author: mdaneri <max.daneri@broadcom.com> Date: Sun Mar 2 10:07:28 2025 -0800 Folder reorganization commit d91b7a5 Author: mdaneri <max.daneri@broadcom.com> Date: Sat Mar 1 14:13:58 2025 -0800 fix powershell support message commit 5d7db37 Author: mdaneri <max.daneri@broadcom.com> Date: Sat Mar 1 04:47:58 2025 -0800 fix tests commit e1f4e24 Author: mdaneri <max.daneri@broadcom.com> Date: Sat Mar 1 03:12:49 2025 -0800 fix tests for 5.1 commit c54d0a6 Author: mdaneri <max.daneri@broadcom.com> Date: Fri Feb 28 07:41:21 2025 -0800 new Digest client module with documentation commit 044070d Author: mdaneri <max.daneri@broadcom.com> Date: Fri Feb 28 06:39:02 2025 -0800 update commit 11a574c Author: mdaneri <max.daneri@broadcom.com> Date: Fri Feb 28 06:18:33 2025 -0800 new Invoke-WebRequestDigest commit ea89876 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 27 12:09:18 2025 -0800 fix Export-Certificate commit 3789b33 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 27 10:58:50 2025 -0800 Update Cryptography.ps1 commit 1ef78ac Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 27 10:53:35 2025 -0800 change parameter Import-PodeCertificate -FilePath to -Path commit 6a42833 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 27 09:20:13 2025 -0800 added digest check for $QualityOfProtection 'auth-int' commit 9f83ecc Author: mdaneri <max.daneri@broadcom.com> Date: Wed Feb 26 10:16:53 2025 -0800 Update DigestAuthentication.Tests.ps1 commit ec6fb18 Author: mdaneri <max.daneri@broadcom.com> Date: Wed Feb 26 10:15:40 2025 -0800 added digest tests commit 6116794 Author: mdaneri <max.daneri@broadcom.com> Date: Tue Feb 25 18:41:45 2025 -0800 test update and fixes commit 76bab58 Author: mdaneri <max.daneri@broadcom.com> Date: Tue Feb 25 15:35:06 2025 -0800 Fix Test and build commit 5758820 Author: mdaneri <max.daneri@broadcom.com> Date: Tue Feb 25 10:50:05 2025 -0800 update tests commit f0ca68e Author: mdaneri <max.daneri@broadcom.com> Date: Tue Feb 25 08:45:44 2025 -0800 Update JWTAuthentication.Tests.ps1 commit 2df6dfe Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 23 21:23:58 2025 -0800 fix mac os issue with ssl commit 72674fc Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 23 18:14:49 2025 -0800 update macOS commit 2f4e5ce Author: MDaneri <max.daneri@broadcom.com> Date: Sun Feb 23 17:18:29 2025 -0800 fix linux mac SSL detection issue commit c3c24d8 Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 23 10:13:51 2025 -0800 update Test-PodeCertificate and SSL documentation commit c42e497 Merge: 6dd871d 67505f5 Author: mdaneri <17148649+mdaneri@users.noreply.github.com> Date: Sun Feb 23 07:30:47 2025 -0800 Merge branch 'develop' into RFC-7616-Compliance commit 6dd871d Author: mdaneri <max.daneri@broadcom.com> Date: Sat Feb 22 18:54:09 2025 -0800 added certificate test commit 04d76a6 Merge: 7db8ff7 cbdc62f Author: mdaneri <max.daneri@broadcom.com> Date: Sat Feb 22 09:17:52 2025 -0800 Merge remote-tracking branch 'upstream/develop' into RFC-7616-Compliance commit 7db8ff7 Author: mdaneri <max.daneri@broadcom.com> Date: Sat Feb 22 09:00:11 2025 -0800 added certificate documentation commit ecc2729 Merge: 908cdaf b40d4e8 Author: mdaneri <max.daneri@broadcom.com> Date: Sat Feb 22 07:32:52 2025 -0800 Merge branch 'RFC-7616-Compliance' of https://github.com/mdaneri/Pode into RFC-7616-Compliance commit 908cdaf Author: mdaneri <max.daneri@broadcom.com> Date: Sat Feb 22 07:32:50 2025 -0800 Fix MacOS EphemeralKeySet issue commit b40d4e8 Merge: 5fc7a00 fbf6ecf Author: mdaneri <17148649+mdaneri@users.noreply.github.com> Date: Sat Feb 22 06:32:32 2025 -0800 Merge branch 'develop' into RFC-7616-Compliance commit 5fc7a00 Author: mdaneri <max.daneri@broadcom.com> Date: Fri Feb 21 16:04:02 2025 -0800 fixex commit 4b0d09c Author: mdaneri <max.daneri@broadcom.com> Date: Fri Feb 21 13:42:52 2025 -0800 fix issue with ephemeral commit 7f06e50 Author: mdaneri <max.daneri@broadcom.com> Date: Fri Feb 21 10:07:28 2025 -0800 revert pode.build commit 5bbd552 Author: mdaneri <max.daneri@broadcom.com> Date: Fri Feb 21 08:57:00 2025 -0800 added certificate management functions commit 6add82d Author: mdaneri <max.daneri@broadcom.com> Date: Wed Feb 19 08:41:14 2025 -0800 added JWT lifecycle commit 601c1cb Author: mdaneri <max.daneri@broadcom.com> Date: Wed Feb 19 08:05:10 2025 -0800 update JWT lifecycle commit 9fd8589 Author: mdaneri <max.daneri@broadcom.com> Date: Tue Feb 18 20:23:19 2025 -0800 update build for 5.1 commit 9a35551 Author: mdaneri <max.daneri@broadcom.com> Date: Tue Feb 18 10:05:39 2025 -0800 Added Update-PodeJWT and support for bearer Body token commit 3939983 Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 16 18:58:13 2025 -0800 moved Authentication example inside Authentication folder commit fc4ed64 Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 16 18:46:34 2025 -0800 Update Cryptography.ps1 commit 74584e9 Author: MDaneri <max.daneri@broadcom.com> Date: Sun Feb 16 18:45:19 2025 -0800 added header to Get-PodeJwtSigningAlgorithm commit cf107b2 Author: MDaneri <max.daneri@broadcom.com> Date: Sun Feb 16 18:17:22 2025 -0800 added workaround for .Net Linux issue commit 6f54b3f Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 16 11:12:37 2025 -0800 macos fixes commit 852d8c0 Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 16 10:58:52 2025 -0800 fixed tests commit 0f0c252 Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 16 10:29:30 2025 -0800 updated comments and documentation commit 7368548 Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 16 09:43:52 2025 -0800 updated to adhere the Pode standard for the certificate commit feb7a2d Merge: 363168b a76741b Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 16 07:06:14 2025 -0800 Merge remote-tracking branch 'upstream/develop' into RFC-7616-Compliance commit 363168b Author: mdaneri <max.daneri@broadcom.com> Date: Sat Feb 15 16:51:30 2025 -0800 Change from PEM cert to PFX and adding 5.1 support commit 84bda14 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 13 09:57:07 2025 -0800 Update Cryptography.Tests.ps1 commit 61072c2 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 13 09:44:17 2025 -0800 Update Cryptography.Tests.ps1 commit 881b72c Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 13 09:28:45 2025 -0800 doc update commit 0e3ae54 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 13 08:22:59 2025 -0800 fix Desktop tests commit 5a2f77f Author: mdaneri <max.daneri@broadcom.com> Date: Thu Feb 13 07:26:32 2025 -0800 Update pode.build.ps1 commit 2bc4d84 Author: MDaneri <max.daneri@broadcom.com> Date: Tue Feb 11 19:32:47 2025 -0800 fix not windows issue commit e98748a Merge: 119d479 a236a1a Author: mdaneri <17148649+mdaneri@users.noreply.github.com> Date: Tue Feb 11 18:47:14 2025 -0800 Merge branch 'develop' into RFC-7616-Compliance commit 119d479 Author: mdaneri <max.daneri@broadcom.com> Date: Tue Feb 11 18:19:20 2025 -0800 working version commit a148489 Author: mdaneri <max.daneri@broadcom.com> Date: Tue Feb 11 10:00:16 2025 -0800 work in progress commit 71315d5 Merge: d5fface e9e7334 Author: mdaneri <max.daneri@broadcom.com> Date: Mon Feb 10 06:47:34 2025 -0800 Merge remote-tracking branch 'upstream/develop' into RFC-7616-Compliance commit d5fface Author: mdaneri <max.daneri@broadcom.com> Date: Mon Feb 10 06:47:15 2025 -0800 added missing header and language entries commit 93fb8ea Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 9 21:00:34 2025 -0800 fixes commit 7a8f61a Merge: 615d4ab 75e2962 Author: mdaneri <max.daneri@broadcom.com> Date: Sun Feb 9 07:21:04 2025 -0800 Merge remote-tracking branch 'upstream/develop' into RFC-7616-Compliance commit 615d4ab Author: mdaneri <max.daneri@broadcom.com> Date: Sat Feb 8 11:23:24 2025 -0800 fix tests and remove Invoke-PodeJWTSign merge Invoke-PodeJWTSign in New-PodeJwtSignature commit 815ca10 Author: mdaneri <max.daneri@broadcom.com> Date: Sat Feb 8 10:16:44 2025 -0800 Enhance Authentication: RFC Compliance, JWT Algorithms, and Bearer Query Support - Added full support for RFC 7518 JWT algorithms: NONE, HS256, HS384, HS512, RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384, ES512. - Introduced `-PrivateKey` parameter in `New-PodeAuthScheme` for RSA and ECDSA JWT signature verification. - Ensured JWT signature validation follows RFC 7518 standards. - Improved JWT validation for `exp` (expiration) and `nbf` (not before) claims. - Added support for passing Bearer tokens via query parameters (`-BearerLocation Query`) as per RFC 6750. - Updated `WWW-Authenticate` handling to correctly return headers on authentication failures for all authentication methods. - Ensured Pode authentication mechanisms align with industry security standards. - Updated documentation to reflect these enhancements. commit 2af345c Merge: 23889e8 6b23fc3 Author: mdaneri <17148649+mdaneri@users.noreply.github.com> Date: Wed Feb 5 13:13:29 2025 -0800 Merge branch 'develop' into RFC-7616-Compliance commit 23889e8 Author: mdaneri <max.daneri@broadcom.com> Date: Fri Jan 31 06:52:55 2025 -0800 Fix markdown commit 4690eff Author: mdaneri <max.daneri@broadcom.com> Date: Fri Jan 31 06:34:56 2025 -0800 update documentation commit b53f07d Author: mdaneri <max.daneri@broadcom.com> Date: Thu Jan 30 10:31:14 2025 -0800 Update Cryptography.ps1 commit 3088db2 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Jan 30 10:11:08 2025 -0800 Fixed tests commit 9090b07 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Jan 30 09:30:23 2025 -0800 add rawdata commit 71d4747 Author: mdaneri <max.daneri@broadcom.com> Date: Thu Jan 30 07:50:04 2025 -0800 Adding auth-int commit ed3a0f5 Author: mdaneri <max.daneri@broadcom.com> Date: Wed Jan 29 18:05:34 2025 -0800 fixes commit 062cc2d Author: mdaneri <max.daneri@broadcom.com> Date: Wed Jan 29 09:01:17 2025 -0800 first drop
1 parent 6539050 commit e7f95a8

89 files changed

Lines changed: 10736 additions & 2007 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.gitignore

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -272,4 +272,8 @@ examples/HelloService/svc_settings
272272

273273
# Dump Folder
274274
Dump
275-
275+
examples/certs/*-public.pem
276+
examples/certs/*-private.pem
277+
tests/certs/*
278+
/examples/certs
279+
examples/Authentication/certs/*

.vscode/settings.json

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,5 +38,13 @@
3838
"javascript.format.insertSpaceBeforeFunctionParenthesis": false,
3939
"[yaml]": {
4040
"editor.tabSize": 2
41+
},
42+
"markdownlint.config": {
43+
"default": true,
44+
"MD045": false,
45+
"MD033": false,
46+
"MD026": {
47+
"punctuation": ".,;:"
48+
}
4149
}
4250
}

README.md

Lines changed: 33 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
<p align="center">
1+
<h1 align="center">
22
<img src="https://github.com/Badgerati/Pode/raw/develop/images/icon-new.svg?raw=true" width="250" />
3-
</p>
3+
</h1>
44

55
[![MIT licensed](https://img.shields.io/badge/license-MIT-blue.svg)](https://raw.githubusercontent.com/Badgerati/Pode/master/LICENSE.txt)
66
[![Documentation](https://img.shields.io/github/v/release/badgerati/pode?label=docs&logo=readthedocs&logoColor=white)](https://badgerati.github.io/Pode)
@@ -53,36 +53,37 @@ Then navigate to `http://127.0.0.1:8000` in your browser.
5353

5454
## 🚀 Features
5555

56-
* Cross-platform using PowerShell Core (with support for PS5)
57-
* Docker support, including images for ARM/Raspberry Pi
58-
* Azure Functions, AWS Lambda, and IIS support
59-
* OpenAPI specification version 3.0.x and 3.1.0
60-
* OpenAPI documentation with Swagger, Redoc, RapidDoc, StopLight, OpenAPI-Explorer and RapiPdf
61-
* Listen on a single or multiple IP(v4/v6) address/hostnames
62-
* Cross-platform support for HTTP(S), WS(S), SSE, SMTP(S), and TCP(S)
63-
* Host REST APIs, Web Pages, and Static Content (with caching)
64-
* Support for custom error pages
65-
* Request and Response compression using GZip/Deflate
66-
* Multi-thread support for incoming requests
67-
* Inbuilt template engine, with support for third-parties
68-
* Async timers for short-running repeatable processes
69-
* Async scheduled tasks using cron expressions for short/long-running processes
70-
* Supports logging to CLI, Files, and custom logic for other services like LogStash
71-
* Cross-state variable access across multiple runspaces
72-
* Restart the server via file monitoring, or defined periods/times
73-
* Ability to allow/deny requests from certain IP addresses and subnets
74-
* Basic rate limiting for IP addresses and subnets
75-
* Middleware and Sessions on web servers, with Flash message and CSRF support
76-
* Authentication on requests, such as Basic, Windows and Azure AD
77-
* Authorisation support on requests, using Roles, Groups, Scopes, etc.
78-
* Support for dynamically building Routes from Functions and Modules
79-
* Generate/bind self-signed certificates
80-
* Secret management support to load secrets from vaults
81-
* Support for File Watchers
82-
* In-memory caching, with optional support for external providers (such as Redis)
83-
* (Windows) Open the hosted server as a desktop application
84-
* FileBrowsing support
85-
* Localization (i18n) in Arabic, German, Spanish, France, Italian, Japanese, Korean, Polish, Portuguese, and Chinese
56+
- ✅ Cross-platform using PowerShell Core (with support for PS5)
57+
- ✅ Docker support, including images for ARM/Raspberry Pi
58+
- ✅ Azure Functions, AWS Lambda, and IIS support
59+
- ✅ OpenAPI specification version 3.0.x and 3.1.0
60+
- ✅ OpenAPI documentation with Swagger, Redoc, RapidDoc, StopLight, OpenAPI-Explorer and RapiPdf
61+
- ✅ Listen on a single or multiple IP(v4/v6) addresses/hostnames
62+
- ✅ Cross-platform support for HTTP(S), WS(S), SSE, SMTP(S), and TCP(S)
63+
- ✅ Host REST APIs, Web Pages, and Static Content (with caching)
64+
- ✅ Support for custom error pages
65+
- ✅ Request and Response compression using GZip/Deflate
66+
- ✅ Multi-thread support for incoming requests
67+
- ✅ Inbuilt template engine, with support for third-parties
68+
- ✅ Async timers for short-running repeatable processes
69+
- ✅ Async scheduled tasks using cron expressions for short/long-running processes
70+
- ✅ Supports logging to CLI, Files, and custom logic for other services like LogStash
71+
- ✅ Cross-state variable access across multiple runspaces
72+
- ✅ Restart the server via file monitoring, or defined periods/times
73+
- ✅ Ability to allow/deny requests from certain IP addresses and subnets
74+
- ✅ Basic rate limiting for IP addresses and subnets
75+
- ✅ Middleware and Sessions on web servers, with Flash message and CSRF support
76+
- ✅ Authentication on requests, such as Basic, Windows and Azure AD
77+
- ✅ Authorisation support on requests, using Roles, Groups, Scopes, etc.
78+
- ✅ Enhanced authentication support, including Basic, Bearer (with JWT), Certificate, Digest, Form, OAuth2, and ApiKey (with JWT).
79+
- ✅ Support for dynamically building Routes from Functions and Modules
80+
- ✅ Generate/bind self-signed certificates
81+
- ✅ Secret management support to load secrets from vaults
82+
- ✅ Support for File Watchers
83+
- ✅ In-memory caching, with optional support for external providers (such as Redis)
84+
- ✅ (Windows) Open the hosted server as a desktop application
85+
- ✅ FileBrowsing support
86+
- ✅ Localization (i18n) in Arabic, German, Spanish, France, Italian, Japanese, Korean, Polish, Portuguese,Dutch and Chinese
8687

8788
## 📦 Install
8889

docs/Tutorials/Authentication/Methods/ApiKey.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -26,13 +26,13 @@ Start-PodeServer {
2626
}
2727
```
2828

29-
By default, Pode will look for an `X-API-KEY` header in the request. You can change this to Cookie or Query by using the `-Location` parameter. To change the name of what Pode looks for, you can use `-LocationName`.
29+
By default, Pode will look for an `X-API-KEY` header in the request. You can change this to Cookie or Query by using the `-ApiKeyLocation` parameter. To change the name of what Pode looks for, you can use `-LocationName`.
3030

3131
For example, to look for an `appId` query value:
3232

3333
```powershell
3434
Start-PodeServer {
35-
New-PodeAuthScheme -ApiKey -Location Query -LocationName 'appId' | Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
35+
New-PodeAuthScheme -ApiKey -ApiKeyLocation Query -LocationName 'appId' | Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
3636
param($key)
3737
3838
# check if the key is valid, and get user

docs/Tutorials/Authentication/Methods/Bearer.md

Lines changed: 163 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -6,13 +6,30 @@ Bearer authentication lets you authenticate a user based on a token, with option
66
Authorization: Bearer <token>
77
```
88

9+
!!! note
10+
**`New-PodeAuthScheme -Bearer` is deprecated.** Please use **`New-PodeAuthBearerScheme`**.
11+
912
## Setup
1013

11-
To start using Bearer authentication in Pode you can use `New-PodeAuthScheme -Bearer`, and then pipe the returned object into [`Add-PodeAuth`](../../../../Functions/Authentication/Add-PodeAuth). The parameter supplied to the [`Add-PodeAuth`](../../../../Functions/Authentication/Add-PodeAuth) function's ScriptBlock is the `$token` from the Authorization token:
14+
To start using Bearer authentication in Pode, call **`New-PodeAuthBearerScheme`**, and then pipe the returned object into [`Add-PodeAuth`](../../../../Functions/Authentication/Add-PodeAuth). The parameter supplied to the [`Add-PodeAuth`](../../../../Functions/Authentication/Add-PodeAuth) function's **ScriptBlock** is the `$token` from the Authorization header.
15+
16+
```powershell
17+
Start-PodeServer {
18+
New-PodeAuthBearerScheme | Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
19+
param($token)
20+
21+
# check if the token is valid, and get user
22+
23+
return @{ User = $user }
24+
}
25+
}
26+
```
27+
28+
By default, Pode will look for a token in the **`Authorization`** header, verifying that it starts with the **`Bearer`** tag. You can customize this tag via **`-HeaderTag`**. You can also change the token extraction location to the **query string** using **`-Location Query`**. For the **`-Location query`** the standard tag is **`access_token`**:
1229

1330
```powershell
1431
Start-PodeServer {
15-
New-PodeAuthScheme -Bearer | Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
32+
New-PodeAuthBearerScheme -Location Query | Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
1633
param($token)
1734
1835
# check if the token is valid, and get user
@@ -22,13 +39,129 @@ Start-PodeServer {
2239
}
2340
```
2441

25-
By default, Pode will check if the request's header contains an `Authorization` key, and whether the value of that key starts with `Bearer` tag. The `New-PodeAuthScheme -Bearer` function can be supplied parameters to customise the tag using `-HeaderTag`.
42+
**Note:** Per [RFC 6750](https://datatracker.ietf.org/doc/html/rfc6750), using the Authorization header is recommended for sending bearer tokens. Query parameters should only be used when headers are not feasible, as query strings may be logged in URLs, potentially exposing sensitive information.
43+
44+
## JWT Support
45+
46+
`New-PodeAuthBearerScheme` supports **JWT authentication** with various security levels and algorithms. Set **`-AsJWT`** to enable JWT validation. Depending on the chosen algorithm, you can specify:
47+
48+
- **HMAC**-based secret keys (`-Secret`)
49+
- **Certificate**-based parameters (`-Certificate`, `-CertificateThumbprint`, `-CertificateName`, `-X509Certificate`, `-SelfSigned`)
50+
- The **RSA padding scheme** (`-RsaPaddingScheme`)
51+
- The **JWT verification mode** (`-JwtVerificationMode`)
52+
53+
### JwtVerificationMode
54+
55+
Defines how aggressively JWT claims should be checked:
56+
57+
- **Strict**: Requires all standard claims:
58+
- `exp` (Expiration Time)
59+
- `nbf` (Not Before)
60+
- `iat` (Issued At)
61+
- `iss` (Issuer)
62+
- `aud` (Audience)
63+
- `jti` (JWT ID)
64+
65+
- **Moderate**: Allows missing `iss` (Issuer) and `aud` (Audience) but still checks expiration (`exp`).
66+
- **Lenient**: Ignores missing `iss` and `aud`, only verifies expiration (`exp`), not-before (`nbf`), and issued-at (`iat`).
67+
68+
### HMAC Example
69+
70+
Here’s an example using **HMAC** (HS256) JWT validation:
71+
72+
```powershell
73+
Start-PodeServer {
74+
New-PodeAuthBearerScheme `
75+
-AsJWT `
76+
-Algorithm 'HS256' `
77+
-Secret (ConvertTo-SecureString "MySecretKey" -AsPlainText -Force) `
78+
-JwtVerificationMode 'Strict' |
79+
Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
80+
param($token)
81+
82+
# validate and decode JWT, then extract user details
83+
84+
return @{ User = $user }
85+
}
86+
}
87+
```
88+
89+
### Certificate-Based Example
90+
91+
For **RSA/ECDSA** JWT validation, you can specify a **certificate** or **thumbprint** instead of a secret key. Pode will infer the appropriate signing algorithms (e.g., RS256, ES256) from the certificate. For instance, using a local **PFX** certificate file:
92+
93+
```powershell
94+
Start-PodeServer {
95+
New-PodeAuthBearerScheme `
96+
-AsJWT `
97+
-Algorithm 'RS256' `
98+
-Certificate "C:\path\to\cert.pfx" `
99+
-CertificatePassword (ConvertTo-SecureString "CertPass" -AsPlainText -Force) `
100+
-JwtVerificationMode 'Moderate' |
101+
Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
102+
param($token)
103+
104+
# validate JWT and extract user
105+
106+
return @{ User = $user }
107+
}
108+
}
109+
```
110+
111+
### Self-Signed Certificate Example
112+
113+
For testing purposes or internal deployments, you can use the **`-SelfSigned`** parameter, which automatically generates an **ephemeral self-signed ECDSA certificate** (ES384) for JWT signing. This avoids the need to manually create and manage certificate files.
114+
115+
#### Example:
116+
117+
```powershell
118+
Start-PodeServer {
119+
New-PodeAuthBearerScheme `
120+
-AsJWT `
121+
-SelfSigned |
122+
Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
123+
param($token)
124+
125+
# validate JWT and extract user
126+
127+
return @{ User = $user }
128+
}
129+
}
130+
```
131+
132+
This is equivalent to manually generating a self-signed ECDSA certificate and passing it via `-X509Certificate`:
133+
134+
```powershell
135+
Start-PodeServer {
136+
$x509Certificate = New-PodeSelfSignedCertificate `
137+
-CommonName 'JWT Signing Certificate' `
138+
-KeyType ECDSA `
139+
-KeyLength 384 `
140+
-CertificatePurpose CodeSigning `
141+
-Ephemeral
142+
143+
New-PodeAuthBearerScheme `
144+
-AsJWT `
145+
-X509Certificate $x509Certificate |
146+
Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
147+
param($token)
148+
149+
# validate JWT and extract user
150+
151+
return @{ User = $user }
152+
}
153+
}
154+
```
155+
156+
Using `-SelfSigned` simplifies setup by automatically handling certificate creation and disposal, making it a convenient choice for local development and testing scenarios.
157+
158+
## Scope Validation
26159

27-
You can also optionally return a `Scope` property alongside the `User`. If you specify any scopes with [`New-PodeAuthScheme`](../../../../Functions/Authentication/New-PodeAuthScheme) then it will be validated in the Bearer's post validator - a 403 will be returned if the scope is invalid.
160+
You can optionally include `-Scope` when creating the scheme. Pode will validate any returned `Scope` from your auth **ScriptBlock** against the scheme’s required scopes. If the scope is invalid, Pode will return 403 (Forbidden).
28161

29162
```powershell
30163
Start-PodeServer {
31-
New-PodeAuthScheme -Bearer -Scope 'write' | Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
164+
New-PodeAuthBearerScheme -Scope 'write' | Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
32165
param($token)
33166
34167
# check if the token is valid, and get user
@@ -38,19 +171,21 @@ Start-PodeServer {
38171
}
39172
```
40173

174+
175+
41176
## Middleware
42177

43-
Once configured you can start using Bearer authentication to validate incoming requests. You can either configure the validation to happen on every Route as global Middleware, or as custom Route Middleware.
178+
Once configured, you can instruct Pode to validate every request with Bearer authentication by using **Global Middleware**, or you can require it on individual Routes.
44179

45-
The following will use Bearer authentication to validate every request on every Route:
180+
**Global Middleware Example** – Validate **every** incoming request:
46181

47182
```powershell
48183
Start-PodeServer {
49184
Add-PodeAuthMiddleware -Name 'GlobalAuthValidation' -Authentication 'Authenticate'
50185
}
51186
```
52187

53-
Whereas the following example will use Bearer authentication to only validate requests on specific a Route:
188+
**Route-Specific Example** – Validate only on a certain Route:
54189

55190
```powershell
56191
Start-PodeServer {
@@ -60,46 +195,42 @@ Start-PodeServer {
60195
}
61196
```
62197

63-
## JWT
64-
65-
You can supply a JWT using Bearer authentication, for more details [see here](../JWT).
66-
67198
## Full Example
68199

69-
The following full example of Bearer authentication will setup and configure authentication, validate the token, and then validate on a specific Route:
200+
Below is a complete example demonstrating Bearer authentication with JWT. It configures a server, sets up JWT validation with a shared secret, and validates requests on one route (`/cpu`) while leaving another (`/memory`) open:
70201

71202
```powershell
72203
Start-PodeServer {
73204
Add-PodeEndpoint -Address * -Port 8080 -Protocol Http
74205
75-
# setup bearer authentication to validate a user
76-
New-PodeAuthScheme -Bearer | Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
77-
param($token)
78-
79-
# here you'd check a real storage, this is just for example
80-
if ($token -eq 'test-token') {
81-
return @{
82-
User = @{
83-
'ID' ='M0R7Y302'
84-
'Name' = 'Morty'
85-
'Type' = 'Human'
206+
# Setup Bearer authentication to validate a user via JWT
207+
New-PodeAuthBearerScheme -AsJWT -Algorithm 'HS256' -Secret (ConvertTo-SecureString "MySecretKey" -AsPlainText -Force) -JwtVerificationMode 'Lenient' |
208+
Add-PodeAuth -Name 'Authenticate' -Sessionless -ScriptBlock {
209+
param($token)
210+
211+
# Example: in real usage, you would decode/verify the JWT fully
212+
if ($token -eq 'test-token') {
213+
return @{
214+
User = @{
215+
'ID' = 'M0R7Y302'
216+
'Name' = 'Morty'
217+
'Type' = 'Human'
218+
}
219+
# Scope = 'read'
86220
}
87-
# Scope = 'read'
88221
}
89-
}
90222
91-
# authentication failed
92-
return $null
93-
}
223+
# authentication failed
224+
return $null
225+
}
94226
95-
# check the request on this route against the authentication
227+
# Validate against the authentication on this route
96228
Add-PodeRoute -Method Get -Path '/cpu' -Authentication 'Authenticate' -ScriptBlock {
97229
Write-PodeJsonResponse -Value @{ 'cpu' = 82 }
98230
}
99231
100-
# this route will not be validated against the authentication
232+
# Open route, no auth required
101233
Add-PodeRoute -Method Get -Path '/memory' -ScriptBlock {
102234
Write-PodeJsonResponse -Value @{ 'memory' = 14 }
103235
}
104236
}
105-
```

0 commit comments

Comments
 (0)