API
Answered
Pyramid ant posted this in #help-forum
data:image/s3,"s3://crabby-images/275c3/275c333dd9c41bfcb60b2ce71c8cd83abb8eb125" alt="Avatar"
Pyramid antOP
Im usining Auth.js and how can i secure the API of th Auth.js ?
Or whole APIs ?
Or whole APIs ?
Answered by B33fb0n3
you can use the middleware for that. Check the auth in your middleware and if he is authorized, let the request run through, else redirect the user to /sign-in or any other route
8 Replies
data:image/s3,"s3://crabby-images/275c3/275c333dd9c41bfcb60b2ce71c8cd83abb8eb125" alt="Avatar"
@Pyramid ant Im usining Auth.js and how can i secure the API of th Auth.js ?
Or whole APIs ?
data:image/s3,"s3://crabby-images/e9035/e9035780a5585406eb6421b82cd580e5dc8561fa" alt="Avatar"
you can use the middleware for that. Check the auth in your middleware and if he is authorized, let the request run through, else redirect the user to /sign-in or any other route
Answer
data:image/s3,"s3://crabby-images/b0351/b0351f7e26cba898e64d8384600f27e4c5758551" alt="Avatar"
i am also encrypting the password between client and server btw @Pyramid ant @B33fb0n3
i suggest you do that too
data:image/s3,"s3://crabby-images/b0351/b0351f7e26cba898e64d8384600f27e4c5758551" alt="Avatar"
@Diamond Master i am also encrypting the password between client and server btw <@1338273633390559324> <@301376057326567425>
data:image/s3,"s3://crabby-images/275c3/275c333dd9c41bfcb60b2ce71c8cd83abb8eb125" alt="Avatar"
Pyramid antOP
Im usining magic links ( API is for login and register )
data:image/s3,"s3://crabby-images/b0351/b0351f7e26cba898e64d8384600f27e4c5758551" alt="Avatar"
@Diamond Master i am also encrypting the password between client and server btw <@1338273633390559324> <@301376057326567425>
data:image/s3,"s3://crabby-images/e9035/e9035780a5585406eb6421b82cd580e5dc8561fa" alt="Avatar"
Yea, I guess it’s basic knowledge that you should look at security, when building an auth system. Even if it’s a library
data:image/s3,"s3://crabby-images/e9035/e9035780a5585406eb6421b82cd580e5dc8561fa" alt="Avatar"
@B33fb0n3 Yea, I guess it’s basic knowledge that you should look at security, when building an auth system. Even if it’s a library
data:image/s3,"s3://crabby-images/b0351/b0351f7e26cba898e64d8384600f27e4c5758551" alt="Avatar"
most websites i see do not encrypt the password lol
they just send it plaintext and rely on https