Authentication with a JavaScript Framework and Node.js

Viewed 167

I have been dealing with the backend stuff for the past month, and I'm done with the following things-

  • Passport Sessions authentication in Vanilla JS (serving EJS files)
  • Passport JWT authentication in Vanilla JS (serving EJS files)
  • Server-side rendering ReactJS (No Authentication)

As of now, I first want to implement Authentication on a simple React project (without SSR), then I'll go for the SSR part.

THE CONFUSION- In every React authentication tutorial I found, people are using backend as an API along with the frontend server (e.g. webpack-dev-server). That makes me a little sceptical about the approach because in all of my React projects till now, I've been using the backend server to serve the static build files emmitted by npm run build. (just what I'd do with EJS files)

Shouldn't using the dev-server cost on performance part? I could not even find a single tutorial on React Authentication that doesn't use development server. I have a few questions-

  1. Is it really a good choice to use the dev-server with backend API? OR Is it even the only way to perform authentication in React? Can't we do this using just the backend server with static files served from build folder?
  2. If I go past simple session-authentication for ReactJS, what should be more secure- JWT or services like Auth0?
  3. What are the techniques used when dealing with an SSR authentication?
0 Answers
Related