Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
REST Authentication with JWT
Search
Ignacio Anaya
November 15, 2017
Programming
110
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
REST Authentication with JWT
Ignacio Anaya
November 15, 2017
More Decks by Ignacio Anaya
See All by Ignacio Anaya
Security is not a feature‼️
ianaya89
2
550
Rompiendo Paradigmas Otra Vuez! 🔨📜3️⃣
ianaya89
0
170
Security is not a feature!
ianaya89
1
410
What's next in Vue 3? 🖖 3️⃣
ianaya89
0
170
What's next in Vue 3? 🖖 3️⃣
ianaya89
0
310
Vue.js, PWA & The Subway Dilemma
ianaya89
0
240
PWA with PWF
ianaya89
0
69
Decentralizing the Web with JavaScript
ianaya89
0
170
hey-devs-time-to-care-about-web-apps-security.pdf
ianaya89
0
140
Other Decks in Programming
See All in Programming
Jetpack Compose メカニズム
skydoves
0
450
MVNOの申込からeSIM開通までをiOSアプリでつなぐ- 本人確認・MNP・通信事業者基盤をまたぐ実装
satotakeshi
0
450
Building an Out-of-Order CPU
latte72
1
790
The Past, Present, and Future of Enterprise Java
ivargrimstad
0
470
AgentCore CLI で進化した AWS での AI エージェントの作り方 : 必要な機能を必要な時に
icoxfog417
PRO
3
360
[GoCon2026] When Goroutines Are Not Enough: Runtime Locality in High-Throughput Go
takehaya
6
2.3k
ゲームコントローラやキーボードのファームウェアをSwiftで書く
kishikawakatsumi
1
250
AGENTS.md Is Not Enough:Build Skills, Don't Download Them
lx_t
0
120
Heart of Swift Concurrency
koher
0
920
WebRTC映像をAirPlayに対応させる挑戦.pdf
monolithic_adam
0
290
cdk deploy JawsSonic #MARATHONしながらAWSリソースをデプロイしてみよう
akihisaikeda
2
140
JPUG勉強会 OSSデータベースの内部構造を理解しよう(第2回)
oga5
0
260
Featured
See All Featured
Optimising Largest Contentful Paint
csswizardry
37
4k
XXLCSS - How to scale CSS and keep your sanity
sugarenia
250
1.3M
Facilitating Awesome Meetings
lara
57
7.1k
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
31
2.9k
Rails Girls Zürich Keynote
gr2m
96
14k
The Power of CSS Pseudo Elements
geoffreycrofte
82
6.6k
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
The Illustrated Guide to Node.js - THAT Conference 2024
reverentgeek
1
510
Ethics towards AI in product and experience design
skipperchong
2
380
Deep Space Network (abreviated)
tonyrice
0
310
The agentic SEO stack - context over prompts
schlessera
0
940
Understanding Cognitive Biases in Performance Measurement
bluesmoon
32
3k
Transcript
REST Authen,ca,on with JWT { REST Authen-ca-on with JWT }
- @ianaya89 1
! Nacho Anaya @ianaya89 • Full Stack Developer, Tech Trainer
& Speaker • Ambassador @Auth0 • Organizer @Vuenos_Aires { REST Authen-ca-on with JWT } - @ianaya89 2
{ REST Authen-ca-on with JWT } - @ianaya89 3
! Why token authen,ca,on? { REST Authen-ca-on with JWT }
- @ianaya89 4
! Why token authen,ca,on? > Stateless { REST Authen-ca-on with
JWT } - @ianaya89 5
! Why token authen,ca,on? > Decoupled { REST Authen-ca-on with
JWT } - @ianaya89 6
! Why token authen,ca,on? > Scalable { REST Authen-ca-on with
JWT } - @ianaya89 7
! Why JWT? { REST Authen-ca-on with JWT } -
@ianaya89 8
! Why JWT? > Standard RFC 7519 { REST Authen-ca-on
with JWT } - @ianaya89 9
! Why JWT? > Self Contained { REST Authen-ca-on with
JWT } - @ianaya89 10
! Why JWT? > Compact { REST Authen-ca-on with JWT
} - @ianaya89 11
! Why JWT? > Signed HMAC - RSA - ECDSA
{ REST Authen-ca-on with JWT } - @ianaya89 12
! Why JWT? > JSON { REST Authen-ca-on with JWT
} - @ianaya89 13
! What is JWT? { REST Authen-ca-on with JWT }
- @ianaya89 14
! What is JWT? header.payload.signature + Base64 { REST Authen-ca-on
with JWT } - @ianaya89 15
! What is JWT? { REST Authen-ca-on with JWT }
- @ianaya89 16
! Header { "alg": "HS256", "typ": "JWT" } { REST
Authen-ca-on with JWT } - @ianaya89 17
! Payload { "id": "1234567890", "name": "John Doe", "admin": true,
"iss": "https://api.com", "exp": 1510745797148 } { REST Authen-ca-on with JWT } - @ianaya89 18
! Payload { "id": "1234567890", "name": "John Doe", "admin": true,
"iss": "https://api.com", "exp": 1510745797148 } { REST Authen-ca-on with JWT } - @ianaya89 19
✍ Signature const data = base64urlEncode( header ) + '.'
+ base64urlEncode( payload ) HMACSHA256(data, 'your_secret_message') { REST Authen-ca-on with JWT } - @ianaya89 20
✍ Signature const data = base64urlEncode( header ) + '.'
+ base64urlEncode( payload ) HMACSHA256(data, 'your_secret_message') { REST Authen-ca-on with JWT } - @ianaya89 21
{ REST Authen-ca-on with JWT } - @ianaya89 22
! When to use it? { REST Authen-ca-on with JWT
} - @ianaya89 23
! When to use it? > Authen)ca)on > Informa*on Exchange
{ REST Authen-ca-on with JWT } - @ianaya89 24
! Where to use it? { REST Authen-ca-on with JWT
} - @ianaya89 25
! Where to use it? SPA's - Mobile Serverless -
IoT { REST Authen-ca-on with JWT } - @ianaya89 26
{ REST Authen-ca-on with JWT } - @ianaya89 27
! { REST Authen-ca-on with JWT } - @ianaya89 28
! REST API's { REST Authen-ca-on with JWT } -
@ianaya89 29
! How does it work with REST? { REST Authen-ca-on
with JWT } - @ianaya89 30
{ REST Authen-ca-on with JWT } - @ianaya89 31
! How does it work with REST? 1. Sends Creden+als
POST /login { "user": "ianaya89", "password": "dont-hack-me" } { REST Authen-ca-on with JWT } - @ianaya89 32
! How does it work with REST? 2. Creates JWT
const jwt = require('jsonwebtoken') // POST /login function login (req, res, next) { // Validates user credentials... const payload = { user: 'ianaya89', role: 'admin' } const token = jwt.sign(payload, 'this_is_super_secret') res.status(201).send({ token: `Bearer ${token}` }) } router.post('/login', login) { REST Authen-ca-on with JWT } - @ianaya89 33
! How does it work with REST? 3. Returns JWT
const jwt = require('jsonwebtoken') // POST /login function login (req, res, next) { // Validates user credentials... const payload = { user: 'ianaya89', role: 'admin' } const token = jwt.sign(payload, 'this_is_super_secret') res.status(201).send({ token: `Bearer ${token}` }) } router.post('/login', login) { REST Authen-ca-on with JWT } - @ianaya89 34
! How does it work with REST? 4. Gets a
resource GET /resource Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9. eyJzdWIiOiIxMjM0NTY3ODkiLCJuYW1lIjoiSm9obiBEb2UiLCJhZG1pbiI6ZmFsc2V9. b99O1RrYbHtWJ3MGZXkdADZkmiLm9HNliRccKxMPDuc { REST Authen-ca-on with JWT } - @ianaya89 35
! How does it work with REST? 5. Verifies token
const jwt = require('jsonwebtoken') // GET /resource function getResource (req, res, next) { try { const payload = jwt.verify(token, 'this_is_super_secret') } catch (err) { return res.sendStatus(401) } } router.get('/resource', getResource) { REST Authen-ca-on with JWT } - @ianaya89 36
! How does it work with REST? 6. Sends response
const jwt = require('jsonwebtoken') // GET /resource function getResource (req, res, next) { try { const payload = jwt.verify(token, 'this_is_super_secret') res.send(' ! ') } catch (err) { return res.sendStatus(401) } } router.get('/resource', getResource) { REST Authen-ca-on with JWT } - @ianaya89 37
! How does it work with REST? 6. Sends response
const jwt = require('jsonwebtoken') // GET /resource function getResource (req, res, next) { try { const payload = jwt.verify(token, 'this_is_super_secret') if (payload.role !== 'admin') { return res.sendStatus(403) } res.send(' ! ') } catch (err) { return res.sendStatus(401) } } router.get('/resource', getResource) { REST Authen-ca-on with JWT } - @ianaya89 38
! Which languages are supported? { REST Authen-ca-on with JWT
} - @ianaya89 39
! Which languages are supported? > "All" of them {
REST Authen-ca-on with JWT } - @ianaya89 40
{ REST Authen-ca-on with JWT } - @ianaya89 41
! Is JWT secure? { REST Authen-ca-on with JWT }
- @ianaya89 42
! { REST Authen-ca-on with JWT } - @ianaya89 43
! Is JWT secure? ! Yes { REST Authen-ca-on with
JWT } - @ianaya89 44
! Is JWT secure? ! But... { REST Authen-ca-on with
JWT } - @ianaya89 45
{ REST Authen-ca-on with JWT } - @ianaya89 46
! Is JWT secure? > Anyone can view the content
{ REST Authen-ca-on with JWT } - @ianaya89 47
! Is JWT secure? > No one can modify it
{ REST Authen-ca-on with JWT } - @ianaya89 48
! Is JWT secure? > JWT is signed not ecnrpyted
{ REST Authen-ca-on with JWT } - @ianaya89 49
! Is JWT secure? > Keep your "secret" secret {
REST Authen-ca-on with JWT } - @ianaya89 50
! Resources • jwt.io • jwt-handbook • demo-auth-jwt-api { REST
Authen-ca-on with JWT } - @ianaya89 51
! { REST Authen-ca-on with JWT } - @ianaya89 52
! Thanks! @ianaya89 bit.ly/rest-auth-jwt { REST Authen-ca-on with JWT }
- @ianaya89 53