authentication

typescript
import { defineConfig, devices } from '@playwright/test';
import path from 'node:path';

export const authFile = path.join(__dirname, '.auth/user.json');

export default defineConfig({

Playwright smoke test for auth flow

testing playwright e2e
by codesnips 4 tabs
ruby
class CreateApiKeys < ActiveRecord::Migration[6.1]
  def change
    create_table :api_keys do |t|
      t.references :user, null: false, foreign_key: true
      t.string :name, null: false
      t.string :key_digest, null: false

API key authentication for service-to-service calls

rails authentication api
by Alex Kumar 3 tabs
ruby
class PasswordResetsController < ApplicationController
  before_action :find_user_by_token, only: [:edit, :update]

  def create
    user = User.find_by(email: params[:email]&.downcase)

Secure password reset flow with signed tokens

rails security authentication
by Alex Kumar 1 tab
java
package com.example.security;

import java.lang.annotation.ElementType;
import java.lang.annotation.Retention;
import java.lang.annotation.RetentionPolicy;
import java.lang.annotation.Target;

Resolve the Authenticated User into a Controller Argument in Spring Boot

spring-boot spring-mvc security
by codesnips 4 tabs
python
import datetime
import jwt
from flask import current_app


class TokenError(Exception):

Token-Based Auth Decorator That Loads current_user Into Flask's g

flask authentication decorators
by codesnips 3 tabs
java
package com.example.github;

import java.util.List;
import retrofit2.Call;
import retrofit2.http.GET;
import retrofit2.http.Path;

Declarative Typed HTTP Client With Retrofit and an OkHttp Auth Interceptor

retrofit okhttp http-client
by codesnips 3 tabs
ruby
require "sinatra/base"
require "rack/utils"

class AdminApp < Sinatra::Base
  before do
    protected!

Protecting Namespaced Admin Routes in Sinatra with an HTTP Basic Auth before Filter

sinatra http-basic-auth authentication
by codesnips 3 tabs
ruby
require 'sinatra/base'
require 'rack/protection'

class TransferApp < Sinatra::Base
  enable :sessions
  set :session_secret, ENV.fetch('SESSION_SECRET', 'a' * 64)

CSRF Protection for Sinatra Forms with Rack::Protection AuthenticityToken

sinatra rack csrf
by codesnips 3 tabs
ruby
user = User.find_by(email: params[:email].to_s.downcase.strip)

if user
  raw_token = SecureRandom.urlsafe_base64(32)
  user.password_resets.create!(token_digest: Digest::SHA256.hexdigest(raw_token), expires_at: 30.minutes.from_now)
  PasswordResetMailer.with(user: user, token: raw_token).deliver_later

Password reset flow that avoids user enumeration and token leaks

password-reset account-enumeration authentication
by Kai Nakamura 1 tab
python
import json
import secrets
import time
from typing import Optional

import redis.asyncio as redis

Sliding-Window Session Token Expiry With FastAPI Middleware and Redis

fastapi redis sessions
by codesnips 3 tabs
java
package com.example.security;

import io.jsonwebtoken.Claims;
import io.jsonwebtoken.Jwts;
import io.jsonwebtoken.JwtException;
import io.jsonwebtoken.io.Decoders;

Stateless JWT Authentication Filter and SecurityFilterChain in Spring Boot

java spring-boot spring-security
by codesnips 3 tabs
java
package com.example.http;

import org.springframework.http.HttpHeaders;
import org.springframework.http.HttpRequest;
import org.springframework.http.client.ClientHttpRequestExecution;
import org.springframework.http.client.ClientHttpRequestInterceptor;

Attaching Bearer Tokens to Spring RestClient Calls with a ClientHttpRequestInterceptor

spring-boot restclient interceptor
by codesnips 3 tabs