← Back to TypeScript Course | Chapter 28: Real World Projects | Lesson 9 of 14

Authentication System की जानकारी

TypeScript authentication requests, user identities, sessions, और authorization decisions model कर सकता है। Strong types public user data को sensitive credentials से अलग रखने में help करते हैं।
Syntax
typescript
interface JwtPayload {
    userId: string;
    role: "admin" | "user";
}

const payload = jwt.verify(token, secret) as JwtPayload;

Core Concept

एक typed authentication system अपने core entities — एक User, एक Session, एक JwtPayload — को explicit interfaces के रूप में model करता है, इसलिए auth data को touch करने वाली हर layer (login handler, middleware, protected route) exactly agree करती है कि कौन से fields present हैं।

उदाहरण: Core Concept

typescript
interface User { id: string; email: string; }
interface Session { userId: string; expiresAt: Date; }
interface JwtPayload { userId: string; role: "admin" | "user"; }
const payload: JwtPayload = { userId: "1", role: "user" };
console.log(payload);

Basic Setup

एक basic setup decoded JWT payload को type करता है (interface JwtPayload { userId: string; role: admin | user }) इसलिए jwt.verify() का return value any के बजाय एक known, specific shape में cast होता है।

उदाहरण: Basic Setup

typescript
interface JwtPayload {
  userId: string;
  role: "admin" | "user";
}
// const decoded = jwt.verify(token, secret) as JwtPayload;
const decoded: JwtPayload = { userId: "1", role: "admin" };
console.log(decoded);

Typed Example

एक typed example: एक Express middleware function requireAuth(req: Request, res: Response, next: NextFunction) जो एक token verify करने के बाद req.user: JwtPayload attach करता है, एक custom Request type augmentation के साथ इसलिए req.user हर जगह downstream recognized हो।

उदाहरण: Typed Example

typescript
interface JwtPayload { userId: string; role: "admin" | "user"; }
function requireAuth(token: string): JwtPayload {
  // In a real app: jwt.verify(token, SECRET) as JwtPayload
  return { userId: "1", role: "user" };
}
console.log(requireAuth("fake-token"));

Project Usage

एक असली project में, role field को एक literal union (admin | user) के रूप में type करना, एक plain string के बजाय, मतलब एक authorization check जैसे if (req.user.role === admni) (एक typo) compile time पर catch होता है, silently हमेशा fail होने के बजाय।

उदाहरण: Project Usage

typescript
type Role = "admin" | "user";
function isAdmin(role: Role): boolean {
  return role === "admin"; // typo like "admni" would be a compile error
}
console.log(isAdmin("admin"));

Best Practices

Typed JWT payload interface में कभी sensitive data जैसे password hash store न करें — payload को सिर्फ वह रखने के लिए type करें जो authorization decisions के लिए ज़रूरी है, token को खुद छोटा और non-sensitive रखते हुए।

उदाहरण: Best Practices

typescript
interface JwtPayload {
  userId: string;
  role: "admin" | "user";
  // No passwordHash here -- keep the token small and non-sensitive.
}
const payload: JwtPayload = { userId: "1", role: "user" };
console.log(payload);
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. role को string के रूप में type करना "admin" | "user" के बजाय, इसलिए "admn" जैसा एक typo compile हो जाता है।
  2. jwt.verify(...) को as JwtPayload cast करना और इस पर trust करना, जब token content runtime पर validate नहीं होता।
  3. Express के Request type को augment किए बिना req.user attach करना, जो एक compile error देता है।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.