Tag: JWT
3 posts
-
OAuth 2.0 & JWT authentication — token login and refresh flows
JWT and OAuth 2.0: sessions vs tokens, authorization code flow, PKCE, token endpoint, scopes and consent, Node.js/Passport, Google and Kakao.
-
JWT Authentication in Node.js: Refresh Token Rotation, HttpOnly Cookies and Revocation
Implement JWT authentication in Node.js and Next.js: short-lived access tokens, rotating refresh tokens with reuse detection, HttpOnly cookie storage, CSRF, Redis revocation, and when sessions are the better choice.
-
Node.js Authentication and Security: JWT, bcrypt, and Sessions
Secure Node.js APIs: bcrypt password hashing, JWT access tokens with pinned algorithms, rotated and hashed refresh tokens, where to store tokens in the browser, sessions with a shared store, Passport OAuth, and the defaults that make auth code insecure.