การใช้งานกลยุทธ์ JWT
ผสานรวมโทเค็นเว็บ JSON (JWT) เพื่อยืนยันตัวตนแบบไม่ใช้สถานะ ครอบคลุมการสร้างและการตรวจสอบโทเค็น
การใช้งานกลยุทธ์ JWT เป็นบทเรียน Next.js 15 Fullstack (App Router + Server Actions) ฟรีบน CoddyKit นี่คือบทเรียนที่ 2 จากทั้งหมด 6 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Next.js 15 Fullstack (App Router + Server Actions) และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Next.js 15 Fullstack (App Router + Server Actions) มีบทเรียนทั้งหมด 6 บทเรียน
บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ
What is a JSON Web Token (JWT)?
Welcome! In this lesson, we'll dive into JSON Web Tokens (JWTs), a popular method for securing APIs.
- JWTs are compact, URL-safe means of representing claims to be transferred between two parties.
- They are often used for stateless authentication, meaning the server doesn't need to store session information.
- This makes APIs more scalable and easier to manage, especially in distributed systems.
JWT's Three Main Parts
A JWT is essentially a long string, but it's structured into three distinct parts, separated by dots (.):
- Header: Contains metadata about the token itself (e.g., type of token, signing algorithm).
- Payload: Contains the actual claims or data about the user and additional properties.
- Signature: Used to verify the token's integrity and authenticity.
Each part is Base64Url-encoded.
Header & Payload in Detail
Let's look closer at the first two parts:
- Header: Typically contains two fields:
"alg"(algorithm, e.g., HS256) and"typ"(type, which is JWT). - Payload: This is where you put your data, known as 'claims'. Common claims include:
sub(subject): Usually the user ID.exp(expiration time): When the token expires.iat(issued at): When the token was issued.- Custom claims: Any other data you need, like
"username"or"role".
The Cryptographic Signature
The signature is the crucial third part that ensures security:
- It's created by taking the encoded header, the encoded payload, a secret key, and the algorithm specified in the header.
- This combination is then cryptographically hashed.
- Why is it important? If anyone tries to tamper with the header or payload, the signature verification will fail, indicating the token is invalid or has been altered.
- The secret key must be kept confidential on the server side!
NestJS and JWTs
NestJS provides excellent support for integrating JWTs, leveraging the power of the jsonwebtoken library under the hood.
We'll primarily use the @nestjs/jwt package, which offers a JwtModule and JwtService to handle token generation and verification seamlessly within your application.
First, you'll need to install the package if you haven't already:
npm install @nestjs/jwt passport-jwt --saveConfiguring the JwtModule
To use JWTs in NestJS, you need to import and configure the JwtModule in your application's module (e.g., AppModule or a dedicated AuthModule).
The most important option is the secret key, which is used to sign and verify tokens.
import { Module } from '@nestjs/common';
import { JwtModule } from '@nestjs/jwt';
@Module({
imports: [
JwtModule.register({
secret: 'yourSuperSecretKey',
signOptions: { expiresIn: '60s' }, // e.g., 60s, 7d, 1h
}),
],
// ... other providers, controllers
})
export class AppModule {}
Generating a JWT in NestJS
Once JwtModule is configured, you can inject JwtService into your services to generate (sign) new tokens. The sign() method takes a payload (usually an object) and creates the JWT string.
import { Injectable } from '@nestjs/common';
import { JwtService } from '@nestjs/jwt';
@Injectable()
export class AuthService {
constructor(private jwtService: JwtService) {}
async signIn(user: any): Promise<string> {
const payload = { username: user.username, sub: user.userId };
return this.jwtService.sign(payload); // Signs with configured secret & options
}
}Code Demo: Token Generation
Let's see how a token is generated conceptually. This example uses the underlying jsonwebtoken library directly, similar to how NestJS does it.
Run this code to see a JWT being created:
// To run this, install 'jsonwebtoken':
// npm install jsonwebtoken --save
const jwt = require('jsonwebtoken');
const payload = {
sub: 'user123',
username: 'coder_kit'
};
const secret = 'mySuperSecretKey123'; // Keep this secret safe!
// Sign the token with an expiration of 1 hour
const token = jwt.sign(payload, secret, { expiresIn: '1h' });
console.log('--- Generated JWT ---');
console.log(token);
console.log('\nThis token is valid for 1 hour.');
Verifying a JWT in NestJS
When a client sends a JWT, your server needs to verify it. The JwtService.verify() method checks several things:
- Is the signature valid (i.e., was it signed with our secret)?
- Has the token expired?
- Are there any other validation rules specified?
If valid, it returns the decoded payload. If invalid, it throws an error.
import { Injectable } from '@nestjs/common';
import { JwtService } from '@nestjs/jwt';
@Injectable()
export class AuthService {
constructor(private jwtService: JwtService) {}
async verifyToken(token: string): Promise<any> {
try {
const payload = this.jwtService.verify(token);
return payload; // Token is valid, return its data
} catch (error) {
// Token is invalid or expired
throw new Error('Invalid or expired token');
}
}
}Code Demo: Token Verification
Here's how token verification works. You can use the token generated in the previous step (or the example provided) and see it being verified.
Remember, the secret used for verification MUST be the same one used for signing!
// To run this, install 'jsonwebtoken':
// npm install jsonwebtoken --save
const jwt = require('jsonwebtoken');
// IMPORTANT: Replace with a REAL token you generated,
// or use this example token (signed with 'mySuperSecretKey123')
const testToken = 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyMTIzIiwidXNlcm5hbWUiOiJjb2Rlcl9raXQiLCJpYXQiOjE3MDcwOTMyMTMsImV4cCI6MTcwNzE3OTYxM30.4i-J_q_e_x_a_m_p_l_e_s_i_g_n_a_t_u_r_e_f_o_r_d_e_m_o';
const secret = 'mySuperSecretKey123'; // Must match the signing secret!
console.log('--- Attempting to Verify Token ---');
try {
const decoded = jwt.verify(testToken, secret);
console.log('Token is VALID!');
console.log('Decoded Payload:');
console.log(decoded);
} catch (error) {
console.error('Token is INVALID or EXPIRED!');
console.error('Error:', error.message);
}
JWT Concept Check
You've learned about the three main parts of a JWT. Which of the following components is primarily responsible for ensuring the token's integrity (that it hasn't been tampered with)?
Recap: JWT Essentials
Great job! You've covered the fundamentals of JWTs:
- What they are: Compact, stateless tokens for authentication.
- Their structure: Header, Payload, and Signature.
- Key concepts: How the signature protects integrity and the role of the secret key.
- NestJS integration: Using
@nestjs/jwtto configure, sign, and verify tokens.
Next, we'll explore how to protect routes using Guards and implement role-based access control!
เรียนรู้ TypeScript ด้วย AI tutor — ฟรี
เขียนและเรียกใช้โค้ดจริงในเบราว์เซอร์ของคุณ รับความช่วยเหลือทันทีจาก AI tutor 24/7 และเรียนรู้ต่อจากที่คุณหยุดบนเว็บหรือในแอป
- คอร์ส
- 22
- บทเรียน
- 88
คำถามที่พบบ่อย
บทเรียน “การใช้งานกลยุทธ์ JWT” ฟรีหรือไม่
ใช่ — ข้อความเต็มของ “การใช้งานกลยุทธ์ JWT” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Next.js 15 Fullstack (App Router + Server Actions) ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Next.js 15 Fullstack (App Router + Server Actions) มีบทเรียนทั้งหมด 6 บทเรียน
คุณจะเรียนรู้อะไรในบทเรียน “การใช้งานกลยุทธ์ JWT”
ผสานรวมโทเค็นเว็บ JSON (JWT) เพื่อยืนยันตัวตนแบบไม่ใช้สถานะ ครอบคลุมการสร้างและการตรวจสอบโทเค็น คุณปฏิบัติ Next.js 15 Fullstack (App Router + Server Actions) ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน
คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Next.js 15 Fullstack (App Router + Server Actions) หรือไม่
ไม่จำเป็นต้องมีประสบการณ์มาก่อน Next.js 15 Fullstack (App Router + Server Actions) บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 2 จากทั้งหมด 6 บทเรียน
บทเรียน “การใช้งานกลยุทธ์ JWT” ใช้เวลานานแค่ไหน
บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย
ฉันเขียนและรันโค้ดในบทเรียน Next.js 15 Fullstack (App Router + Server Actions) นี้ได้ไหม
ได้ บทเรียน Next.js 15 Fullstack (App Router + Server Actions) ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ
บทเรียนทั้งหมดในหลักสูตรนี้
- การผสาน NextAuth.js
- การใช้งานกลยุทธ์ JWT
- การปกป้องเส้นทางและข้อมูล
- การ์ดและบทบาท
- กลยุทธ์การยืนยันตัวตนแบบกำหนดเอง
- การผสานรวม Passport.js