Tag: Authentication
7 posts
-
OAuth 2.0 & JWT authentication — token login and refresh flows
JWT and OAuth 2.0: sessions vs tokens, authorization code flow, PKCE, token endpoint, scopes and consent, Node.js/Passport, Google and Kakao.
-
Authentication with Passport.js: Local Login, Google and GitHub OAuth, JWT and Session Stores
Adding authentication to Node.js with Passport.js: local username/password login, protected routes, Google and GitHub OAuth, JWT strategy, combining strategies, and production session stores.
-
Password Hashing with bcrypt in Node.js: Cost Factors, the 72-Byte Limit and Thread Pool Pitfalls
Hashing passwords with bcrypt in Node.js: choosing a cost factor, the 72-byte input limit, thread pool saturation, reset tokens, and the login and ORM-hook pitfalls that quietly weaken it.
-
JWT Authentication in Node.js: Refresh Token Rotation, HttpOnly Cookies and Revocation
Implement JWT authentication in Node.js and Next.js: short-lived access tokens, rotating refresh tokens with reuse detection, HttpOnly cookie storage, CSRF, Redis revocation, and when sessions are the better choice.
-
Building on Firebase: Firestore Data Modeling, Security Rules, Auth and Cloud Functions
Building production apps with Firebase: Firestore data modeling and real-time listeners, security rules, authentication patterns, Cloud Storage, Cloud Functions, and cost control.
-
Adding Auth to Next.js with Clerk: clerkMiddleware, Protected Routes, Webhooks and Orgs
Clerk auth in a Next.js App Router app with @clerk/nextjs v7: clerkMiddleware, auth.protect(), the Show component, verified webhooks for user sync and org roles.
-
Node.js Authentication and Security: JWT, bcrypt, and Sessions
Secure Node.js APIs: bcrypt password hashing, JWT access tokens with pinned algorithms, rotated and hashed refresh tokens, where to store tokens in the browser, sessions with a shared store, Passport OAuth, and the defaults that make auth code insecure.