OO
All work

Live

Aurhanticator

A training project that shows an authentication API. Accounts, hashed passwords, JWT sessions, and protected routes. The pages are a thin front so the API can be tried in a browser.

  • Node.js
  • Express
  • MongoDB
  • JWT
  • bcrypt
Aurhanticator website
Visit the site — Live demo

/ Problem

A client that can read document.cookie should not be able to steal a long-lived refresh token. The API had to separate a short-lived access token from a refresh token the page script cannot read.

/ My role

I built the API in an MVC layout with Express and MongoDB, then put a few pages in front of it so a sign-in can be checked in the browser.

/ What I built

  1. 01Routes, controllers, and a Mongoose user model.
  2. 02Passwords hashed with bcrypt before they are stored.
  3. 03A short JWT access token, and a refresh cookie the page cannot read.
  4. 04Protected routes that check the access token first.
  5. 05A success page after register or login, so the session can be confirmed.

Refresh-token rotation, rate limiting, and automated tests are not part of what this demo shows.

/ One hard part

Two tokens, two jobs

The access token is what a request presents. The refresh token stays in an HTTP-only cookie so frontend JavaScript cannot read it. Protected routes check the access token and fail through the same error path as a bad login.