dbsc-toolkit
Device Bound Session Credentials (DBSC) for Node.js — middleware that binds session cookies to a hardware TPM key to stop cookie theft, with a Web Crypto polyfill for Firefox & Safari.
File Explorer
- bug_report.md
- ci.yml
- codeql.yml
- release-better-auth.yml
- release.yml
- dependabot.yml
- PULL_REQUEST_TEMPLATE.md
- banner.png
- demo.gif
- tier.png
- what-stealer-sees.png
- dbsc-explained.md
- implementing-dbsc-on-express.md
- implementing-dbsc-server-side.md
- what-dbsc-protects.md
- best-practices.md
- threat-model.md
- .nojekyll
- adapters.md
- api-reference.md
- deployment.md
- docs.html
- dpop.md
- faq.md
- guide.md
- index.html
- polyfill.md
- protocol.md
- quickstart.md
- README.md
- recipes.md
- request-signing.md
- robots.txt
- sitemap.xml
- storage.md
- telemetry.md
- troubleshooting.md
- index.html
- auth.js
- server.js
- package.json
- README.md
- index.html
- jwt.html
- server.js
- .gitignore
- package.json
- server.js
- package.json
- server.js
- package.json
- 001_initial.sql
- 002_bound_key_kind.sql
- 003_v2_tier_and_challenge_cascade.sql
- adapter.ts
- client.ts
- cookies.ts
- index.ts
- init-script.ts
- internal.ts
- routes.test.ts
- routes.ts
- schema.ts
- LICENSE
- package.json
- README.md
- tsconfig.json
- vitest.config.ts
- bound-refresh.json
- bound-registration.json
- dpop-bound-token.json
- dpop-htu-normalization.json
- dpop-proof.json
- per-request-proof.json
- README.md
- refresh.json
- registration-header.json
- registration.json
- 01-overview.md
- 02-native-protocol.md
- 03-bound-protocol.md
- 04-per-request-proof.md
- 05-crypto.md
- 06-storage-contract.md
- 07-cookies.md
- 08-errors.md
- 09-conformance.md
- 10-dpop.md
- README.md
- clockSync.ts
- index.test.ts
- index.ts
- installFetchInterceptor.test.ts
- installFetchInterceptor.ts
- keystore.ts
- wrapFetch.ts
- index.ts
- proof.test.ts
- proof.ts
- refresh.test.ts
- refresh.ts
- registration.test.ts
- registration.ts
- verify.ts
- options.test.ts
- options.ts
- jwk.test.ts
- jwk.ts
- jws.test.ts
- jws.ts
- bind.ts
- guard.ts
- htu.test.ts
- htu.ts
- index.ts
- thumbprint.ts
- vectors.test.ts
- verify.test.ts
- verify.ts
- challenge.test.ts
- challenge.ts
- cookies.test.ts
- cookies.ts
- headers.ts
- refresh.ts
- registration.test.ts
- registration.ts
- security-fixes.test.ts
- skipped.test.ts
- interface.ts
- interface.ts
- hooks.ts
- polyfill-missing.ts
- memory-storage-stub.ts
- derive-session-id.test.ts
- derive-session-id.ts
- errors.ts
- index.ts
- protect-policy.test.ts
- protect-policy.ts
- types.ts
- index.ts
- create-dbsc.ts
- electron.test.ts
- index.ts
- require-dpop.ts
- require-proof.ts
- bind-session.test.ts
- bound-disabled.test.ts
- bound-routes.test.ts
- cookie-scope.test.ts
- create-dbsc.ts
- index.ts
- proof.ts
- require-dpop.test.ts
- require-dpop.ts
- require-proof.ts
- response-shape.test.ts
- bound-routes.test.ts
- create-dbsc.ts
- index.ts
- proof.ts
- require-dpop.ts
- require-proof.ts
- bound-routes.test.ts
- context-shape.test.ts
- create-dbsc.ts
- index.ts
- proof.ts
- require-dpop.ts
- require-proof.ts
- bound-routes.test.ts
- create-dbsc.ts
- index.ts
- require-dpop.ts
- require-proof.ts
- guard.test.ts
- index.ts
- bound-routes.test.ts
- create-dbsc.ts
- index.ts
- proof.ts
- require-dpop.ts
- require-proof.ts
- bound-routes.test.ts
- create-dbsc.ts
- index.ts
- require-dpop.test.ts
- require-dpop.ts
- require-proof.ts
- index.test.ts
- index.ts
- replay-cache.test.ts
- replay-cache.ts
- index.ts
- index.ts
- replay-cache.ts
- handle.test.ts
- index.ts
- require-dpop.ts
- require-proof.ts
- index.ts
- .gitignore
- CHANGELOG.md
- CONTRIBUTING.md
- HOW-IT-WORKS.md
- LICENSE
- package-lock.json
- package.json
- pnpm-lock.yaml
- pnpm-workspace.yaml
- README.md
- ROADMAP.md
- SECURITY.md
- tsconfig.json
- tsconfig.test.json
- vitest.config.ts
# Use via CDN
jsDelivrjsDelivr serves any public GitHub repository as a CDN with zero setup. Pick a version and a file to get a ready-to-paste link and snippet.
Link
Example
// repository documentation
Was this content helpful?
(0 ratings)
