57 | Authentication and Authorization and Other Buzz Words

Compressed.fm

In this episode, James and Amy, explain all the buzz words: authentication, authorization, JWTs, sessions, and cookies. And what's the best implementation for your site?

In this episode, James and Amy, explain all the buzz words: authentication, authorization, JWTs, sessions, and cookies. And what's the best implementation for your site?

Sponsors

Vercel

Vercel combines the best developer experience with an obsessive focus on end-user performance. Their platform enables frontend teams to do their best work. It is the best place to deploy any frontend app. Start by deploying with zero configuration to their global edge network. Scale dynamically to millions of pages without breaking a sweat.

For more information, visit Vercel.com

ZEAL is hiring!

ZEAL is a computer software agency that delivers “the world’s most zealous” and custom solutions. The company plans and develops web and mobile applications that consistently help clients draw in customers, foster engagement, scale technologies, and ensure delivery.

ZEAL believes that a business is “only as strong as” its team and cares about culture, values, a transparent process, leveling up, giving back, and providing excellent equipment. The company has staffers distributed throughout the United States, and as it continues to grow, ZEAL looks for collaborative, object-oriented, and organized individuals to apply for open roles.

For more information visit softwareresidency.com/careers

DatoCMS

DatoCMS is a complete and performant headless CMS built to offer the best developer experience and user-friendliness in the market. It features a rich, CDN-powered GraphQL API (with realtime updates!), a super-flexible way to handle dynamic layouts and structured content, and best-in-class image/video support, with progressive/LQIP image loading out-of-the-box."

For more information, visit datocms.com

Show Notes

  • 0:00 Introduction
  • 4:30 Unpopular Opinions and Parenting Tips
  • 8:55 All the Buzzwords
  • 10:38 What would you do if you were to build authentication and authorization into your own site?
  • 12:08 Authentication VS Authorization
  • 15:57 Sponsor: DatoCMS
  • 16:51 Roles and Permissions
  • 20:18 Cookies and Sessions
  • 25:45 Facebook Tracking
  • 27:04 The Relationship Between Sessions and Cookies
  • 29:28 Sponsor: ZEAL
  • 30:21 JWTs, JSON, and Web Tokens
  • 35:35 Combining JWTs with Cookies
  • 36:45 Beware: Cross Side Scripting
  • 38:53 Refresh Tokens
  • 41:22 Identity / SaaS Platforms for to Handle Authentication
  • 46:32 Sponsor: Vercel
  • 47:40 Grab Bag Questions
  • 48:06 Question #1: Is it JWT or JOT?
  • 50:31 Question #2: Rolling your own Auth System vs. Using a Service
  • 51:19 Question #3: What is your favorite Girl Scout Cookie?
  • 52:33 Picks and Plugs
  • 52:46 Amy's Pick: CodeSpark
  • 54:18 Amy's Plug: Everything Svelte
  • 54:57 James's Pick: Publix Sub Sandwich
  • 56:28 James's Plug: Learn Build Teach Discord

Audio Player

-
--:--
--:--