Authentication

Passionate Software Developer with a strong enthusiasm for data, technology, and entrepreneurship to solve real-world problems. I enjoy building innovative digital solutions and currently exploring new advancements in data, and leveraging my skills to create impactful software solutions. Beyond coding, I have a keen interest in strategic thinking in business and meeting new people to exchange ideas and collaborate on exciting projects.
Authentication is the process of verifying the identity of a user, system, or entity before granting access to resources. It answers the question: “Who are you?”, ensuring that only legitimate users or systems can access data or perform operations.
Authorization on the other hand verifies permissions (What are you allowed to do after logging in?).
Importance of Authentication
Security: Authentication ensures only authorized users can access the system in order to safeguard sensitive information from unauthorized users.
Data Integrity: Authentication maintains the integrity of data within the system by controlling access, reducing risk of malicious data manipulation or theft.
User Verification: It confirms the identity of users, ensuring each user can only access information and perform actions within their permitted scope.
Prevention of Unauthorized Access: Authentication prevent attackers from guessing or using stolen credentials, thereby adding essential layer of security.
Some of the most common authentication strategies include the following:
Session-based authentication
JWT
Oauth
Session-based authentication
This is a method of identifying users in subsequent requests after they have logged in once. It involves the following;
User sends a login request with an ID and password to the server, which then verifies the provided authentication information, and establishes a session if it’s correct. Session information is stored both on the server and in a cookie.
The sends a response back to the client indicating a session has been established.
The client sends a request to the server with session information, indicating the user is authenticated, and the server responds back indicating the user is authorized and allowed access to specific resources.
When the client requests to logout, the server deletes the session from the server and cookie, invalidating the session information. The server then sends a response back to the client, indicating that the session has been successfully terminated.
JSON Web Tokens (JWT)
JWT provides a stateless way to authenticate. It is a compact, URL-safe way of representing pieces of information between the client and server in a secure manner.
JWT involves the following:
A user logs in by sending their credentials via HTTP request to the server which validates these credentials against those in the database.
If credentials don’t match, access is denied. If they match, server geenrates a JWT token which includes encoded details about the user, i.e., user identity, a signature, and optional expiration timestamp.
The JWT is then sent to the client as part of the response to a successful login. The client stores this locally in localStorage, or session storage instead of cookies.
For subsequent requests, the client includes the JWT in the HTTP header (Done using Authorization header with ‘Bearer’ as prefix followed by the token)
Upon receiving the request, the server validates the token’s signature and checks the validity against expiration date. If the token is valid, the server trusts the request and processes it as authenticated, retrieving user information from the token payload as needed.
When user decides to logout, the client discards the stored JWT. Since the server doesn’t store session information with JWT, no server-side action is required to end the session.
NOTE: Reason why JWT is preferred is because there is no need for storing anything on the server side.
Oauth
Oauth stands for Open Authorization. It is an open standard protocol that allows a user to grant one application limited access to their resources on another service without sharing their credentials.
Instead of handing out your password to every app, OAuth lets you give them a token issued by the service you trust (Google, Facebook, Spotify, etc.). That token has limited scope, time, and permissions.
Here is how Oauth works:
When a user wants to login with Oauth provider like Google, Facebook, etc, the provide first authenticates the user’s identity (involves user logging into the Oauth provider with their credentials).
After authenticating the user, Oauth issues an access token to the requesting application. This token doesn’t contain authentication information per se but signifies that the issuing authority (Oatuh provider) has authenticated the user at some point in time.
The client application can use the access token to make API requests to the Oauth provider to fetch user details. This process indirectly uses Oauth as part of the authentication process by verifying the token and retrieving user details from the trusted Oauth provider.
Because the access token is a credential issued by the OAuth provider post-authentication, client applications often treat the presence of a valid token as confirmation that the OAuth provider has authenticated the user. Thus, the application indirectly authenticates the user based on the OAuth provider’s earlier authentication process.
For subsequent requests to access the user’s resources, the client application includes the access token in the HTTP header. The resource server validates the access token and, if valid, responds with the requested data.
When the user logs out, the client application discards the access token and may optionally inform the OAuth provider to invalidate the token. This action effectively ends the session from the client’s perspective, as the token can no longer be used to access the user’s resources.


