0Pricing
Node.js Backend Development Bootcamp · درس

البرمجيات الوسيطة للمصادقة باستخدام JWT

أضف مصادقة آمنة إلى تطبيق Express باستخدام JSON Web Tokens، وتعلّم كيفية حماية المسارات باستخدام برمجية وسيطة مخصصة للمصادقة.

البرمجيات الوسيطة للمصادقة باستخدام JWT درس مجاني في Node.js Backend Development Bootcamp على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Node.js Backend Development Bootcamp، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Node.js Backend Development Bootcamp 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Why Tokens?

HTTP is stateless: the server forgets you between requests. To know who is making a request, the client sends proof of identity each time.

JSON Web Tokens (JWT) are a popular, stateless way to carry that proof without storing sessions on the server.

Anatomy of a JWT

A JWT is three Base64 sections separated by dots:

  • Header: the signing algorithm
  • Payload: claims like user id and role
  • Signature: verifies the token was not tampered with

The payload is encoded, not encrypted — never put secrets in it.

// xxxxx.yyyyy.zzzzz
// header.payload.signature

Installing jsonwebtoken

The jsonwebtoken package handles creating and verifying tokens.

// npm install jsonwebtoken
const jwt = require('jsonwebtoken');

Signing a Token on Login

After verifying a user's credentials, call jwt.sign() with the payload, a secret, and options like expiry. Send the resulting token back to the client.

const token = jwt.sign(
  { userId: user.id, role: user.role },
  process.env.JWT_SECRET,
  { expiresIn: '1h' }
);
res.json({ token });

Sending the Token

The client stores the token and sends it back on each request, usually in the Authorization header using the Bearer scheme.

// Authorization: Bearer eyJhbGci...

Reading the Token in Middleware

Auth middleware extracts the token from the header. Split off the Bearer prefix to get the raw token string.

function auth(req, res, next) {
  const header = req.get('Authorization') || '';
  const token = header.split(' ')[1];
  // verify next...
}

Verifying the Token

jwt.verify() checks the signature and expiry. If valid it returns the decoded payload; if not it throws, so wrap it in try/catch.

try {
  const payload = jwt.verify(token, process.env.JWT_SECRET);
  req.user = payload;
  next();
} catch (err) {
  res.status(401).json({ error: 'Invalid token' });
}

Complete Auth Middleware

Putting it together, this middleware rejects missing or invalid tokens and attaches the user to the request for downstream handlers.

function auth(req, res, next) {
  const token = (req.get('Authorization') || '').split(' ')[1];
  if (!token) return res.status(401).json({ error: 'No token' });
  try {
    req.user = jwt.verify(token, process.env.JWT_SECRET);
    next();
  } catch {
    res.status(401).json({ error: 'Invalid token' });
  }
}

Protecting Routes

Apply the middleware to any route that requires login. Express runs it before the handler, blocking unauthenticated requests automatically.

app.get('/profile', auth, (req, res) => {
  res.json({ id: req.user.userId });
});

Role-Based Authorization

Authentication answers "who are you?"; authorization answers "are you allowed?". A second middleware can check req.user.role set by the auth step.

function requireAdmin(req, res, next) {
  if (req.user.role !== 'admin') {
    return res.status(403).json({ error: 'Forbidden' });
  }
  next();
}
app.delete('/users/:id', auth, requireAdmin, handler);

Security Best Practices

Keep tokens safe:

  • Store the secret in an environment variable, never in code
  • Use short expiry times and refresh tokens for longer sessions
  • Always serve over HTTPS
  • Return 401 for missing/invalid auth, 403 for insufficient permissions

Quick Check

Test your understanding of JWT auth.

Recap

You built stateless authentication with JWT:

  • Sign a token on login with jwt.sign()
  • Send it via the Authorization: Bearer header
  • Verify it in custom middleware with jwt.verify()
  • Attach req.user and protect routes
  • Add role checks for authorization

This is the foundation of secure Express APIs.

الأسئلة الشائعة

هل درس «البرمجيات الوسيطة للمصادقة باستخدام JWT» مجاني؟

نعم — نص درس «البرمجيات الوسيطة للمصادقة باستخدام JWT» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Node.js Backend Development Bootcamp، انتقل إلى CoddyKit PRO. تتضمن دورة Node.js Backend Development Bootcamp 4 دروس في المجموع.

ماذا ستتعلم في «البرمجيات الوسيطة للمصادقة باستخدام JWT»؟

أضف مصادقة آمنة إلى تطبيق Express باستخدام JSON Web Tokens، وتعلّم كيفية حماية المسارات باستخدام برمجية وسيطة مخصصة للمصادقة. تتمرن على Node.js Backend Development Bootcamp مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Node.js Backend Development Bootcamp؟

لا تُشترط خبرة سابقة. Node.js Backend Development Bootcamp على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «البرمجيات الوسيطة للمصادقة باستخدام JWT»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Node.js Backend Development Bootcamp هذا؟

نعم. كل درس في Node.js Backend Development Bootcamp يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. تطوير برمجيات وسيطة مخصّصة في Express
  2. استراتيجيات معالجة الأخطاء العامة
  3. التحقق من المدخلات باستخدام Joi/Express-Validator
  4. البرمجيات الوسيطة للمصادقة باستخدام JWT
← العودة إلى Node.js Backend Development Bootcamp