← Back to Node.js Course | Chapter 8: Working with APIs | Lesson 5 of 7

Authentication के Basics

Authentication prove करता है caller कौन है; common choices API keys, sessions, और tokens हैं।

In this page:

  1. Authentication Basics

Authentication Basics

कभी plain passwords store न करें; bcrypt या scrypt से hash करें। Login के बाद, एक session cookie या JWT जैसा एक signed token issue करें और हर request पर इसे verify करें। Secrets सिर्फ HTTPS पर भेजें। Authorization, यह decide करना कि एक user क्या कर सकता है, एक separate step है।

Note: Node का built-in crypto.scrypt बिना extra packages के passwords hash कर सकता है।

उदाहरण: Authentication basics

javascript
const crypto = require("crypto");
function hash(password, salt = crypto.randomBytes(8).toString("hex")) {
  return salt + ":" + crypto.scryptSync(password, salt, 16).toString("hex");
}
function verify(password, stored) {
  const [salt] = stored.split(":");
  return hash(password, salt) === stored;
}
const stored = hash("s3cret");
console.log("right:", verify("s3cret", stored));
console.log("wrong:", verify("nope", stored));

// Output:
// right: true
// wrong: false

⚠️ Run this in your own terminal or Node.js environment.

Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. plain passwords store करना
  2. source code में secrets डालना
  3. authentication को authorization से confuse करना
चैप्टर सारांश
  • Passwords hash करें
  • Tokens या sessions users identify करते हैं
  • HTTPS इस्तेमाल करें
  • Authorization separate है
🔒

Chapter Quiz — Complete all 7 topics to unlock

0/7 topics done

Complete these topics first:

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.