I am during create a chat-app. I want to find a good way to safely connect front and backend using a TokenId from firebase auth.
- Do I have to in every request from my front to backend send a TokenId?
- It is possible to do it in session or something like that I can send token once and verified it once time too?
My code front end where I send a token:
fetch('http://localhost:5500/check', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
},
body: JSON.stringify({ token: token }),
})
.then(data => data.json())
.then(e => console.log(e))
.catch(err => console.log(err));
});
I get token on front end like that:
firebase.auth().currentUser.getIdToken(true)
My code backend verify token:
router.post('/check', urlencodedParser, (req, res) => {
const {token} = req.body;
admin
.auth()
.verifyIdToken(token)
.then(function (decodedToken) {
// let uid = decodedToken.uid;
res.setHeader('Content-Type', 'application/json');
res.send({status: 'Ok'});
})
.catch(function (error) {
console.log(error);
res.setHeader('Content-Type', 'application/json');
res.send({status: 'err'});
});
});
