JSON Web Tokens (JWTs) are being prescribed as a panacea for webapp security, but you need to know your security basics before you can implement them with peace of mind. JWTs are a great mechanism for persisting authentication information in a verifiable and stateless way, but that token still needs to be secured.
In this talk, Robert Damphousse, lead front-end developer at Stormpath, will discuss JWTs and how they should be used for front-end applications. Examples will reference AngularJS, but the concepts are useful for React (or any other front-end framework). Topics covered will be:
- Mitigating XSS (Cross-Site Scripting)
- Mitigating CSRF (Cross-Site-Request-Forgery)
- How to use cookies securely
- Why JSON Web Tokens (JWTs) are useful
- Oauth2: Access Token, or Refresh Token? Answer: Both!
- How to store JWTs in the browser
http://forwardjs.com/
Angular2 Training - Instructor-led online training from NewCircle:
https://newcircle.com/instructor-led-...
In this talk, Robert Damphousse, lead front-end developer at Stormpath, will discuss JWTs and how they should be used for front-end applications. Examples will reference AngularJS, but the concepts are useful for React (or any other front-end framework). Topics covered will be:
- Mitigating XSS (Cross-Site Scripting)
- Mitigating CSRF (Cross-Site-Request-Forgery)
- How to use cookies securely
- Why JSON Web Tokens (JWTs) are useful
- Oauth2: Access Token, or Refresh Token? Answer: Both!
- How to store JWTs in the browser
http://forwardjs.com/
Angular2 Training - Instructor-led online training from NewCircle:
https://newcircle.com/instructor-led-...
JWT Authentication with AngularJS - Forward 4 Web Summit java sdk | |
112 Likes | 112 Dislikes |
8,977 views views | 157K followers |
Science & Technology | Upload TimePublished on 7 Mar 2016 |
Không có nhận xét nào:
Đăng nhận xét