JWT Authentication and Roles
Harry
· 22 Sep 2026
· 1 views
Log in to track your progress and mark lessons complete.
Sponsored
Flow
Login returns access plus refresh tokens; attach Bearer headers; on 401 refresh and retry, else log out.
Roles
Admin has full CRUD plus reports; staff can read and edit but not delete.
Enforcement
RequireAuth guards routes for UX; every API endpoint re-checks the role server-side.
Key Points
- Short-lived access, httpOnly refresh.
- Seed one admin and one staff user.
- Never trust role claims from the client alone.