This is the most basic implementation of JWT-based authentication.
422
This is the most basic implementation of JWT-based authentication using login and password credentials. Upon successful login, the server returns a signed JWT in the response body, which the client must store and send with each request using the Authorization header. The security middleware verifies the JWT token, extracts the user ID from its payload, and injects this ID into the request object for downstream processing.
⚠ Security Advisory: Current JWT authentication level lacks production-grade security measures
Authorization: Bearer <token> header required for protected routes, ensuring that only authenticated users can access sensitive data or perform critical actions./api, providing a clear understanding of available endpoints and parameters.The journey begins when a user attempts to register or log in through our application. They send their credentials (login and password) to one of two routes:
/auth/sign-up: For new users who want to create an account./auth/sign-in: For existing users who need to authenticate.The server receives the user's request and verifies their credentials against the database. If everything checks out, we proceed with the next step.
Upon successful verification, the server generates a JSON Web Token (JWT) for the user. This token contains essential information about the user, such as their ID.
The client-side application receives the JWT token from the server and stores it securely for future use. You can use LocalStorage or SessionStorage to store the token on the client side.
When a user attempts to access a protected route, their client-side application sends the stored JWT token in an Authorization header with each request:
Authorization: Bearer <token>
The backend server receives the request and verifies the validity of the JWT token. If everything checks out, it grants access to the protected route.
| Method | Endpoint | Description | Required Body |
|---|---|---|---|
| POST | /auth/sign-up | Register a new user and get JWT | login: string, password: string |
| POST | /auth/sign-in | Login and get JWT | login: string, password: string |
For a detailed overview of the available API endpoints, request/response structures, and data models, the Swagger documentation is available at /api. This documentation provides interactive API exploration and helps developers understand and integrate with the API efficiently.
POST /auth/sign-up
{
"login": "Pier228
"password": "password123"
}
{
"token": "eyJhbGciOiJIUzI1NiIsInR5..."
}
Authorization: Bearer <token>
This JWT authentication implementation is designed for educational purposes or prototyping, but it's not recommended for production use due to several security limitations. The current implementation falls short in several critical areas:
To ensure the application is working correctly, comprehensive testing has been implemented to cover all aspects of the JWT authentication flow. The application utilizes Supertest for E2E testing, which allows making HTTP requests directly from test code and verifying expected responses. Here's a snapshot of the test results:
As you can see, all tests passed successfully. This gives confidence in the correctness of the JWT authentication implementation and ensures it works as expected in different scenarios. You can also run this test cases using npm run test:e2e command.
$ git clone https://github.com/Pier228/ultimate-auth-guide.git
$ cd jwt-based-auth
$ cd level-0-basic-token-auth
$ npm install
The Docker image for this project is available on Docker Hub.
To run this application, you need to configure several environment variables.
PORT: The port on which the server will run. This field is optional. By default will run on 3000 port.DATABASE_URL: MongoDB connection URL used to connect to the database.SALT_ROUNDS: Number of rounds for hashing passwords (bcrypt).JWT_SECRET: Secret key for signing and verifying JWT tokens.CORS_ALLOWED_ORIGIN: The URL of the domain from which it is allowed to send requests to the server (CORS settings).You can also refer to the .env.example file for a complete list of required environment variables.
After setting up the .env file, you can start the application using the following commands:
# Generate prisma client
$ npx prisma generate
# Build the application
$ npm run build
# Start in development mode
$ npm run start
# Start in watch mode
$ npm run start:dev
# Start in production mode
$ npm run start:prod
This project is licensed under the MIT License - see the LICENSE file for details.
Content type
Image
Digest
sha256:0067df3a8…
Size
272.3 MB
Last updated
over 1 year ago
docker pull pier276/level-0-basic-token-auth