Code Explainers

Code explainers tagged #authentication

typescript
import { Body, Controller, Ip, Post, UnauthorizedException } from '@nestjs/common';
import { Throttle, ThrottlerGuard } from '@nestjs/throttler';
import { UseGuards } from '@nestjs/common';
import { AuthService } from './auth.service';

Rate-limiting an auth flow in NestJS

rate-limiting authentication guards
Intermediate 8 steps
php
<?php
 
namespace App\Services;
 

How user impersonation works in Laravel

authentication authorization session
Intermediate 8 steps
python
import secrets
 
from fastapi import Depends, FastAPI, HTTPException, Security, status
from fastapi.security import APIKeyHeader

API key authentication as a FastAPI dependency

authentication dependency-injection api-keys
Intermediate 8 steps
php
<?php
 
final class RememberMeCookie
{

Signed remember-me cookies in PHP

authentication hmac cookies
Intermediate 8 steps
java
@Component
public class RefreshTokenSuccessHandler implements AuthenticationSuccessHandler {
 
    private final RefreshTokenService refreshTokenService;

Issuing JWT and refresh tokens on login in Spring

authentication jwt http-cookies
Intermediate 7 steps
python
from datetime import timedelta
 
from flask import Blueprint, current_app, make_response, redirect, request, url_for
from itsdangerous import URLSafeTimedSerializer, BadSignature, SignatureExpired

How signed remember-me cookies work in Flask

authentication signed-cookies session-management
Intermediate 8 steps
ruby
class ApplicationController < ActionController::Base
  ALLOWED_REDIRECT_HOSTS = [nil, ENV.fetch("APP_HOST", "app.example.com")].freeze
 
  def store_return_to(location = request.fullpath)

Safe post-login redirects in Rails

open-redirect session authentication
Intermediate 9 steps
ruby
module Authenticatable
  extend ActiveSupport::Concern
 
  included do

JWT authentication as a Rails concern

authentication jwt concerns
Intermediate 6 steps
java
public final class HmacJwt {
 
    private static final ObjectMapper MAPPER = new ObjectMapper();
    private static final Base64.Encoder ENCODER = Base64.getUrlEncoder().withoutPadding();

How HMAC-signed JWTs are created and verified

jwt hmac cryptography
Intermediate 9 steps
python
import base64
import hashlib
import hmac
import os

How TOTP two-factor codes work

totp hmac authentication
Intermediate 7 steps
typescript
interface JwtPayload {
  exp?: number;
  iat?: number;
  sub?: string;

Decoding a JWT to check expiry

jwt base64url type-guards
Intermediate 8 steps
javascript
const express = require('express');
const cookieParser = require('cookie-parser');
 
const router = express.Router();

Remember-me login with signed cookies in Express

authentication signed-cookies sessions
Intermediate 9 steps
ruby
require "openssl"
require "json"
require "base64"
 

Building signed session tokens in Ruby

hmac authentication cryptography
Intermediate 8 steps
javascript
const express = require('express');
const jwt = require('jsonwebtoken');
const crypto = require('crypto');
 

Refresh token rotation in Express

jwt token-rotation authentication
Advanced 9 steps
ruby
require "net/http"
require "json"
require "uri"
require "base64"

Paginating an HTTP API with a Ruby enumerator

pagination http enumerator
Intermediate 7 steps
go
package admin
 
import (
	"net/http"

Building a protected admin area in Gin

routing middleware authentication
Intermediate 6 steps
go
package security
 
import (
	"crypto/hmac"

Signing and verifying payloads with HMAC in Go

hmac cryptography authentication
Intermediate 5 steps
typescript
import {
  CanActivate,
  ExecutionContext,
  Injectable,

How guards chain auth in NestJS

guards authentication authorization
Intermediate 8 steps