Syntax - Tasty Web Development Treats

How To Build Your Own Auth

Mar 17, 2021
Dive into the world of building custom authentication! Discover the ins and outs of JWT, secure cookies, and effective session management. Learn about the transition from built-in solutions to personalized systems and the nuances of password hashing and security best practices. The podcast also examines the critical role of HTTPS in protecting cookie transmission and addresses the complexities of Cross-Origin Resource Sharing (CORS). Plus, enjoy personal anecdotes that lighten up these technical discussions!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Session-Based Auth

  • Use a session-based approach with access and refresh tokens for better control.
  • Track sessions in a database table to manage active logins.
INSIGHT

Password Transmission

  • Passwords sent during registration are plain text but secured by SSL.
  • Encrypting passwords client-side is pointless due to key accessibility.
ADVICE

Salting and Hashing

  • Always salt and hash passwords before storing them in your database.
  • This protects against data breaches by making it hard to decrypt stolen hashes.
Get the Snipd Podcast app to discover more snips from this episode
Get the app