REST API Token-based Authentication

Let me seperate up everything and solve approach each problem in isolation: Authentication For authentication, baseauth has the advantage that it is a mature solution on the protocol level. This means a lot of “might crop up later” problems are already solved for you. For example, with BaseAuth, user agents know the password is a … Read more

CSRF Token necessary when using Stateless(= Sessionless) Authentication?

I found some information about CSRF + using no cookies for authentication: https://auth0.com/blog/2014/01/07/angularjs-authentication-with-cookies-vs-token/ “since you are not relying on cookies, you don’t need to protect against cross site requests” http://angular-tips.com/blog/2014/05/json-web-tokens-introduction/ “If we go down the cookies way, you really need to do CSRF to avoid cross site requests. That is something we can forget when … Read more

Angular redirect to login page

Here’s an updated example using Angular 4 (also compatible with Angular 5 – 8) Routes with home route protected by AuthGuard import { Routes, RouterModule } from ‘@angular/router’; import { LoginComponent } from ‘./login/index’; import { HomeComponent } from ‘./home/index’; import { AuthGuard } from ‘./_guards/index’; const appRoutes: Routes = [ { path: ‘login’, component: … Read more

Set cookies for cross origin requests

Cross site approach To allow receiving & sending cookies by a CORS request successfully, do the following. Back-end (server) HTTP header settings: Set the HTTP header Access-Control-Allow-Credentials value to true. Make sure the HTTP headers Access-Control-Allow-Origin and Access-Control-Allow-Headers are set. Don’t use a wildcard *. When you set the allowed origin make sure to use … Read more

Change GitHub Account username

Yes, it’s possible. But first read, “What happens when I change my username?” To change your username, click your profile picture in the top right corner, then click Settings. On the left side, click Account. Then click Change username. See the pictures below: Settings Change username Confirm changing username Type the new username Confirm the … Read more

Single sign-on flow using JWT for cross domain authentication

Redirecting the user to the central authentication service when the user is not logged in to request credentials and issue a new authentication token is the common scenario in Single Sign On systems using well-known protocols like oauth2 or OpenId Connect However when this schema is used across domains the main drawback is that the … Read more

Creating an API for mobile applications – Authentication and Authorization

The way I’m thinking about doing the login part of this in my projects is: before login the user requests a login_token from the server. These are generated and stored on the server on request, and probably have a limited lifetime. to login the application calculates the hash of the users password, then hashes the … Read more