How Laravel Auth works with Token JWT?

Viewed 77

The user login in with Auth::atempt(), and this generates an authentication "state" in Laravel - the auth::user().

At the same time, I can generate a JWT token with, for example, the same data as auth::user() and send it to the frontend, storing it in local storage.

OK. Only with auth::user() I could already check the user's authorization to perform actions, right? For example:

if(auth::user()->role === "admin") { //... }

So, what is the purpose of JWT values if they are the same of the auth facade? Because Laravel would already authenticate with auth, and it store all user values that can be used for authorization, so I don't understand the purpose of using it with Laravel.

My application uses the react scaffolding, and is a frontend SPA.

0 Answers
Related