Authentication: JWT, OAuth basics
Web Technologies · Engineering
Study notes
Login: verify bcrypt hash, issue JWT {userId, exp} signed; client sends in Authorization header; server verifies signature, no session lookup. Google login: OAuth flow redirects, Google confirms identity, app gets token. Logout: client discards JWT (or blacklist). Refresh tokens extend.