Authentication
Rules
- Session-based auth for web apps — JWT only for API-to-API
- Middleware for route protection — check session before rendering
- Social providers: Google + GitHub minimum — add more based on audience
- Magic links as password alternative — simpler, more secure
- Role-based access:
user.rolefield with middleware checks - CSRF protection on all mutation endpoints
- Secure cookie settings:
httpOnly,secure,sameSite: "lax", propermaxAge - Refresh token rotation — don't let tokens live forever
Avoid
- Storing tokens in localStorage — use httpOnly cookies
- Rolling your own password hashing — use bcrypt/argon2 via your auth library
- Client-side role checks without server validation
- Missing CSRF protection on form submissions