Authentication System की जानकारी
In this page:
interface JwtPayload {
userId: string;
role: "admin" | "user";
}
const payload = jwt.verify(token, secret) as JwtPayload;
Core Concept
एक typed authentication system अपने core entities — एक User, एक Session, एक JwtPayload — को explicit interfaces के रूप में model करता है, इसलिए auth data को touch करने वाली हर layer (login handler, middleware, protected route) exactly agree करती है कि कौन से fields present हैं।
उदाहरण: Core Concept
interface User { id: string; email: string; }
interface Session { userId: string; expiresAt: Date; }
interface JwtPayload { userId: string; role: "admin" | "user"; }
const payload: JwtPayload = { userId: "1", role: "user" };
console.log(payload);
Basic Setup
एक basic setup decoded JWT payload को type करता है (interface JwtPayload { userId: string; role: admin | user }) इसलिए jwt.verify() का return value any के बजाय एक known, specific shape में cast होता है।
उदाहरण: Basic Setup
interface JwtPayload {
userId: string;
role: "admin" | "user";
}
// const decoded = jwt.verify(token, secret) as JwtPayload;
const decoded: JwtPayload = { userId: "1", role: "admin" };
console.log(decoded);
Typed Example
एक typed example: एक Express middleware function requireAuth(req: Request, res: Response, next: NextFunction) जो एक token verify करने के बाद req.user: JwtPayload attach करता है, एक custom Request type augmentation के साथ इसलिए req.user हर जगह downstream recognized हो।
उदाहरण: Typed Example
interface JwtPayload { userId: string; role: "admin" | "user"; }
function requireAuth(token: string): JwtPayload {
// In a real app: jwt.verify(token, SECRET) as JwtPayload
return { userId: "1", role: "user" };
}
console.log(requireAuth("fake-token"));
Project Usage
एक असली project में, role field को एक literal union (admin | user) के रूप में type करना, एक plain string के बजाय, मतलब एक authorization check जैसे if (req.user.role === admni) (एक typo) compile time पर catch होता है, silently हमेशा fail होने के बजाय।
उदाहरण: Project Usage
type Role = "admin" | "user";
function isAdmin(role: Role): boolean {
return role === "admin"; // typo like "admni" would be a compile error
}
console.log(isAdmin("admin"));
Best Practices
Typed JWT payload interface में कभी sensitive data जैसे password hash store न करें — payload को सिर्फ वह रखने के लिए type करें जो authorization decisions के लिए ज़रूरी है, token को खुद छोटा और non-sensitive रखते हुए।
उदाहरण: Best Practices
interface JwtPayload {
userId: string;
role: "admin" | "user";
// No passwordHash here -- keep the token small and non-sensitive.
}
const payload: JwtPayload = { userId: "1", role: "user" };
console.log(payload);
roleकोstringके रूप में type करना"admin" | "user"के बजाय, इसलिए"admn"जैसा एक typo compile हो जाता है।jwt.verify(...)कोas JwtPayloadcast करना और इस पर trust करना, जब token content runtime पर validate नहीं होता।- Express के
Requesttype को augment किए बिनाreq.userattach करना, जो एक compile error देता है।
Chapter Quiz — Complete all 14 topics to unlock
0/14 topics done
Complete these topics first:
- Todo App with TypeScript
- REST API with Express + TypeScript
- React Dashboard with TypeScript
- CLI Tool with TypeScript
- Library with TypeScript
- Full Stack TypeScript App
- TypeScript Design System
- TypeScript Monorepo Project
- Authentication System
- Real-time App with Socket.io
- GraphQL API with TypeScript
- Microservices with TypeScript
- TypeScript Best Practices Review
- What to Learn Next