, this session is valid. Register and login both land here, so the sign-in is something you can see.
Signed in as
Email
Joined
Why this project exists
Backend training by Omar Othman.
The goal is to show Omar Othman's experience creating a backend. Aurhanticator is that practice: an MVC authentication API, with a small frontend so the API can be used and judged.
Backend
What the API shows
Express MVC: routes, controllers, and a Mongoose user model.
MongoDB for accounts, with bcrypt hashes instead of plain passwords.
JWT access tokens that last 15 minutes, and an httpOnly refresh cookie that lasts 7 days.
A verifyJWT middleware that locks /users and /auth/me.
CORS with credentials so the browser can keep the session.
Frontend
What the pages show
Pug pages rendered by the same Express app.
A Tailwind interface for home, register, login, this success page, and the directory.
Forms that call the JSON API, with client-side checks before the request.
A session that restores itself and refreshes the access token when it expires.
A searchable directory that only renders after the API accepts the token.