Urgent.News

What's breaking now, across thousands of outlets.

Tech

Building a Choose-Your-Own-Adventure API with NestJS — Part 4: Auth

Part 4 of the Grimoire API series. So far: a validated endpoint ( Part 1 ), persistence ( Part 2 ), and the actual XP/badge rules ( Part 3 ) — all running against one hardcoded "default player." This post finally gets rid of that placeholder. Retiring DEFAULT_PLAYER_ID Since Part 2, every POST /progress/choice call has quietly advanced the same fake user. It was a deliberate shortcut to build…

Part 4 of the Grimoire API series brings real accounts and authentication to the project. The previous stages focused on validated endpoints, persistence, and the XP/badge rules. This post finally replaces the placeholder DEFAULT_PLAYER_ID with genuine user accounts. Every progress endpoint will now be scoped to the authenticated user.

NestJS simplifies authentication by wrapping Passport, a widely-used Node authentication library, behind its own decorators. Two Passport strategies are employed to meet the project's requirements: the Local strategy for email and password login, and the JWT strategy for validating bearer tokens on subsequent requests.

A Guard is responsible for blocking requests before reaching a controller method if authentication fails. The JwtAuthGuard class is a simple wrapper that uses the jwt strategy from @nestjs/passport to handle authentication.

Password hashing is crucial for security. The bcrypt library is used to hash passwords during sign-up and compare them during login. The cost factor (10 in bcrypt.hash(password, 10)) determines the number of hashing rounds, balancing speed and security. In this case, 10 is a reasonable default for a learning project, but production environments may require further tuning.

The JWT strategy, implemented in JwtStrategy, uses PassportStrategy to handle token validation. It extracts the token from the authentication header using fromAuthHeaderAsBearerToken, and the JWT_SECRET is fetched from environment variables. The validate method then checks the payload and returns the user object, which is signed and returned as an access token using the jwtService.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Resumv: a resume editor you can deploy as a static site

Resumv is an MIT-licensed resume editor built with Astro and React. Its deployment model is deliberately small: build the project, serve the static output, and let the browser handle resume editing…

  • Resumv is an open-source resume editor under MIT license
  • Uses Astro and React for static site deployment
  • Supports 15 templates, PDF rendering, and export formats

Moving on-premises block storage to AWS? The "divide by 625 MBps" sizing approach comes out wrong

Moving on-premises block storage to AWS? The "divide by 625 MBps" sizing approach comes out wrong — measured session and queue counts What this article does and does not cover: it covers the measured…

  • Dividing throughput by 625 MBps to determine sessions is inaccurate.
  • Testing shows method fails to capture system's true potential.
  • Approach not recommended for AWS block storage sizing.

More from Wednesday 30 September →