I have this problem with Express(NodeJS)/Angular web app where I rely on Steam's login authentication. Essentially when the user clicks "Login" he's redirected to the Steam authentication(Steam's website), once logged in the user is redirected back to a specific route on my backend called /verify. Once the user hits /verify there are session variables containing necessary user data to access. Therefore I use JWT to generate a token with this data to send back to the client(Angular in this case).
The problem is sending this token back to the frontend(the client) to save in local storage.
Any help is highly appreciated! Currently, I pass the token via a query string with a redirect back to the frontend, but this doesn't seem like a good solution.
Maybe I should stick to server-side sessions and write HTTP routes to GET user data. The problem with this approach is once again the client is completely unaware when the user authenticates himself on the backend, since the only callback is triggered is on the backend.
EDIT: Tried another approach, however once again unsure of it's the right way to go both code-wise and security-wise.
- Redirect the user to the Steam authentication page.
- Wait for the authentication callback on server side, in my case it hits the route '/verify'.
- Once at /verify the session cookie is already set, therefore I redirect the user back to my Angular app to a specific route called '/login'.
- On /login the user requests a token based on the session cookie on the server, the token in my case is a JSON Web Token(JWT).
- Once the token is saved in local storage I simply redirect the user to any page in my Angular app.
If this is the wrong way to do it, please let me know!