auth-patterns

Solid

JWT access/refresh tokens, Passport.js strategies, session management, OAuth. Use when implementing authentication, authorization, or setting up OAuth providers in a NestJS + Next.js app.

AI & Automation 30 stars 9 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 82/100

Stars 20%
50
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Auth Patterns ## JWT Access + Refresh Token Flow ``` Login → API issues access_token (15min) + refresh_token (7d) → Frontend stores access_token in memory, refresh_token in httpOnly cookie Request → Attach Authorization: Bearer <access_token> → If 401 → POST /auth/refresh with httpOnly cookie → If refresh valid → new access_token → If refresh expired → redirect to login ``` ## NestJS Auth Module ```typescript // auth/auth.module.ts @Module({ imports: [ PassportModule, JwtModule.registerAsync({ inject: [ConfigService], useFactory: (config: ConfigService) => ({ secret: config.get('JWT_SECRET'), signOptions: { expiresIn: '15m' }, }), }), UsersModule, ], controllers: [AuthController], providers: [ AuthService, JwtStrategy, LocalStrategy, JwtRefreshStrategy, ], exports: [AuthService], }) export class AuthModule {} ``` ## Strategies ```typescript // auth/strategies/local.strategy.ts import { Strategy } from 'passport-local' import { PassportStrategy } from '@nestjs/passport' @Injectable() export class LocalStrategy extends PassportStrategy(Strategy) { constructor(private auth: AuthService) { super({ usernameField: 'email' }) } async validate(email: string, password: string): Promise<AuthUser> { const user = await this.auth.validateCredentials(email, password) if (!user) throw new UnauthorizedException('Invalid email or password') return user } } // auth...

Details

Author
sabahattink
Repository
sabahattink/antigravity-fullstack-hq
Created
8 months ago
Last Updated
5 days ago
Language
PowerShell
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category