Authentication के Basics
Authentication prove करता है caller कौन है; common choices API keys, sessions, और tokens हैं।
In this page:
Authentication Basics
कभी plain passwords store न करें; bcrypt या scrypt से hash करें। Login के बाद, एक session cookie या JWT जैसा एक signed token issue करें और हर request पर इसे verify करें। Secrets सिर्फ HTTPS पर भेजें। Authorization, यह decide करना कि एक user क्या कर सकता है, एक separate step है।
Note:
Node का built-in crypto.scrypt बिना extra packages के passwords hash कर सकता है।
उदाहरण: Authentication basics
const crypto = require("crypto");
function hash(password, salt = crypto.randomBytes(8).toString("hex")) {
return salt + ":" + crypto.scryptSync(password, salt, 16).toString("hex");
}
function verify(password, stored) {
const [salt] = stored.split(":");
return hash(password, salt) === stored;
}
const stored = hash("s3cret");
console.log("right:", verify("s3cret", stored));
console.log("wrong:", verify("nope", stored));
// Output:
// right: true
// wrong: false
⚠️ Run this in your own terminal or Node.js environment.
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the
view already swaps in the hi_ translation fields (or blanks these
out if untranslated), so this renders correctly for both languages
without a lang_code check here. #}
आम गलतियां
- plain passwords store करना
- source code में secrets डालना
- authentication को authorization से confuse करना
चैप्टर सारांश
- Passwords hash करें
- Tokens या sessions users identify करते हैं
- HTTPS इस्तेमाल करें
- Authorization separate है
🔒
Chapter Quiz — Complete all 7 topics to unlock
0/7 topics done
Complete these topics first: