登录与 JWT 生成
构建用户登录系统,签发并管理 JSON Web Token(JWT),实现会话管理。
登录与 JWT 生成 是 CoddyKit 上的免费 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 AI Powered SaaS: Stripe + Auth + Billing + Deploy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Welcome to Login Systems
In the previous lesson, we learned about user registration and secure password hashing. Now, it's time to build the login system!
A login system allows authenticated users to access protected resources and personalize their experience within your SaaS application.
How Login Works (Overview)
When a user tries to log in, they typically provide a username (or email) and a password. Here's the basic flow:
- The client (e.g., your mobile app) sends credentials to the server.
- The server verifies these credentials against its stored user data.
- If valid, the server grants access.
Verifying User Credentials
Upon receiving login credentials, your server needs to perform a crucial check:
- Find the user by their unique identifier (e.g., email or username).
- Retrieve the stored hashed password for that user.
- Compare the provided password (after hashing it with the same method) with the stored hashed password.
Never store passwords in plain text! Always hash and salt them, as we discussed in the registration lesson.
The Challenge: Stateless APIs
Modern APIs are often stateless, meaning the server doesn't remember previous requests from the same client. This makes APIs scalable but poses a challenge for user authentication.
How do we know if a user who just logged in is still authenticated on their next request without sending credentials every time?
Introducing JSON Web Tokens (JWT)
JSON Web Tokens (JWTs) are a compact, URL-safe means of representing claims to be transferred between two parties. They are perfect for stateless authentication.
Instead of server-side sessions, the server issues a JWT upon successful login. The client then stores this token and sends it with every subsequent request.
JWT Structure: Header
A JWT consists of three parts separated by dots: Header, Payload, and Signature.
The Header typically contains two parts:
typ(type of token, usually 'JWT')alg(signing algorithm, e.g., 'HS256' for HMAC SHA256)
It's a JSON object, Base64Url-encoded.
{"alg":"HS256","typ":"JWT"}JWT Structure: Payload (Claims)
The Payload contains the 'claims' – statements about an entity (usually the user) and additional data.
Claims can be:
- Registered: Standard fields like
sub(subject),exp(expiration time),iat(issued at time). - Public: Custom claims defined by you, but registered in the IANA JSON Web Token Registry.
- Private: Custom claims agreed upon by the parties using them, like
userIdorrole.
Example Payload:
{"sub":"12345","name":"Coddy User","exp":1700000000}JWT Structure: Signature
The Signature is crucial for verifying the token's integrity. It's created by taking the encoded header, the encoded payload, and a secret key, then applying the algorithm specified in the header.
If anyone tries to tamper with the header or payload, the signature verification will fail, making the token invalid. The secret key is known only to the server.
Generating a JWT (Conceptual)
After successfully verifying a user's credentials, your server generates a JWT. This involves:
- Creating the Header and Payload JSON objects.
- Base64Url-encoding both.
- Concatenating them with a dot.
- Signing the combined string using a secret key and the chosen algorithm to produce the Signature.
The final JWT is EncodedHeader.EncodedPayload.Signature.
JWT Generation Example
While full JWT signing requires a library, we can demonstrate the Base64 encoding part of building a JWT string. This ensures the token is URL-safe.
import java.util.Base64;
import java.nio.charset.StandardCharsets;
public class Main {
public static void main(String[] args) {
String headerJson = "{\"alg\":\"HS256\",\"typ\":\"JWT\"}";
String payloadJson = "{\"sub\":\"user123\",\"name\":\"Coddy User\"}";
String encodedHeader = Base64.getUrlEncoder().withoutPadding().encodeToString(headerJson.getBytes(StandardCharsets.UTF_8));
String encodedPayload = Base64.getUrlEncoder().withoutPadding().encodeToString(payloadJson.getBytes(StandardCharsets.UTF_8));
System.out.println("Header (Base64Url-encoded):\n" + encodedHeader);
System.out.println("\nPayload (Base64Url-encoded):\n" + encodedPayload);
System.out.println("\nConceptual JWT structure: " + encodedHeader + "." + encodedPayload + ".[Signature]");
}
}Quick Check: JWT Parts
You've just learned about the three main parts of a JSON Web Token (JWT).
Recap: Login & JWTs
Great job! You've learned how a user login system works and the role of JSON Web Tokens (JWTs) in modern, stateless authentication.
- Login involves verifying credentials against hashed passwords.
- JWTs provide a stateless way to manage user sessions.
- JWTs have three parts: Header, Payload, and Signature.
- The Signature ensures the token's integrity.
Next, we'll explore how to use these JWTs to protect your API routes!
用 AI 导师学习 AI Powered SaaS: Stripe + Auth + Billing + Deploy — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 48
常见问题解答
「登录与 JWT 生成」课时是免费的吗?
是的 — 「登录与 JWT 生成」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课程的其余内容,请升级到 CoddyKit PRO。 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课程共包含 4 节课。
「登录与 JWT 生成」这节课中我会学到什么?
构建用户登录系统,签发并管理 JSON Web Token(JWT),实现会话管理。 你通过在浏览器中直接运行的动手代码来练习 AI Powered SaaS: Stripe + Auth + Billing + Deploy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 AI Powered SaaS: Stripe + Auth + Billing + Deploy 需要有经验吗?
无需任何先前经验。CoddyKit 上的 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。
「登录与 JWT 生成」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课中编写并运行代码吗?
能。每节 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 用户注册与哈希处理
- 登录与 JWT 生成
- 受保护路由与中间件
- 密码重置与电子邮件验证