Who Are Vue? Authn In Vue, The Important Parts

Rate this content
Bookmark

In the ever-evolving landscape of modern single-page applications, VueJS stands out but also presents us with challenges. Among them, authentication is crucial: ensuring the user's identity and securing their journey within your application. Fear not; we're here to guide you through these exciting frontiers. In my session, I'll unravel the secrets of authentication in VueJS applications, making it a delightful learning journey for everyone while keeping the focus on the most critical parts. I'll provide an overview of an authentication flow, break down each step, and demystify the role of JWT tokens in the process. 


Whether you're a seasoned VueJS developer or just getting started, you're welcome. A dash of prior experience with user authentication certainly doesn't hurt, but it's optional. 


Target audience: Web Developers of all levels who want to learn about security topics and best practices.


Key learnings:

- Giving a small introduction to the most essential terms and concepts of Authentication;

- VueJS is used as an example, but the concepts will be agnostic.

This talk has been presented at Vue.js Live 2024, check out the latest edition of this JavaScript Conference.

FAQ

The main topic of the Vue.js Live talk is authentication, specifically how to implement it in Vue.js applications.

The speaker of the Vue.js Live talk is Ramona, a developer advocate at Auth0, Google Developer Expert in web technologies, Women Techmaker Ambassador, and Cypress Ambassador.

According to the Oxford Dictionary, authentication is the process or action of proving or showing something to be true, genuine, or valid. In software engineering, it refers to verifying the identity of a user or process.

Authentication is the process of verifying who the user is, while authorization determines what an authenticated user is allowed to do within an application.

The three factors used in authentication are: something you know (e.g., username and password), something you have (e.g., cell phone or YubiKey), and something you are (e.g., fingerprints or face ID).

Single factor authentication is a method of authentication that uses only one of the three authentication factors, such as a username and password.

The purpose of the backend mock in the Vue.js example is to simulate a backend server and database for the purpose of demonstrating a simple authentication flow.

The JSON Web Toolkit library is used in the Vue.js example for handling JSON Web Tokens.

The code example for the Vue.js authentication flow can be found on StackBlitz and GitHub, as mentioned by the speaker.

If you cannot scan the QR code provided in the talk, the speaker will share the slides later, so you don't need to worry.

Ramona Schwering
Ramona Schwering
23 min
25 Apr, 2024

Comments

Sign in or register to post your comment.
Video Summary and Transcription
This Talk introduces authentication in Vue.js and emphasizes that it is not as difficult as it may seem. The speaker explains the concept of authentication and its importance. A code example is used to demonstrate how to implement authentication in Vue.js, including separate UI parts for login, home, and dashboard views. The Talk also covers handling authentication in the Vue.js router, including defining routes, accessing user credentials, and making requests to the backend.

1. Introduction to Authentication in Vue.js

Short description:

Hello, everyone. I want to talk with you about authentication in Vue.js. It's not as intimidating as it may seem. Authentication is the process of verifying the identity of a user or process. I will focus on the most important aspects, without going into a deep dive.

Hello, everyone. I'm so happy to have you here at Vue.js Live this year in April. Well, I don't want to spoil you too much. So I want to start with this fact. I saw something you did in this real world some days before, and I know that you did it because you're here, you're watching my talk. To be able to do so, you need to get a ticket. Maybe it's even connected to your name. And with this ticket, with this access, you are able to join me here. So in order to join me, you need to authenticate yourself, right? And this is actually what I want to talk with you about, authentication, but only the most important part. So you can have the same learning as I had, that it's not that intimidating as it might look like.

Well, don't get me wrong. It's in a way it's good that it's intimidating, because it shows that you are taking the responsibility seriously for such a workflow, which is important and needs to be kept secure. But you don't need to be scared when it comes to implementing it into Vue, and I will show you. But before that, real quick, my name is Ramona. I'm working as a developer advocate at Auth0. But besides that, I'm a Google developer expert in web technologies, a Women Techmaker Ambassador, and a Cypress Ambassador. And unlike the last times where I talked with you about testing, this time I want to talk with you about security-related topics, especially when it comes to such a sensitive workflow as a login. It's equally important, if not more important than software quality, and it's entangled.

So yeah, let's start. So I asked you the question, who are you indirectly when it comes to being able to enter this conference? But answering the question, who are you, or who are you, actually, is something you do a lot of times when it comes to your work life, your day-to-day. But also when it comes to web development, or even in movies, it happens. Just as in this short film, which is called Who Are You?, which was directed by Julio Poz in 2019. And basically the film's about answering this question, and imagine if someone asked it, we will answer with our whole life story, which I do think that every one of us here knows that it's nothing we need to answer, right? So no matter if you are asked, who are you in real life, or if you have some cases inside of your applications where this answer needs to be given, you take a valid answer, a short answer, but a secure one, so the person asking it, or the service asking it, can be sure that you are who you are. You can be sure when it comes to the process of authentication. But let's define what authentication really is, to have a shared sense of understanding, so we know what we are talking about. The first part I did was looking it up in Oxford Dictionary, and they say that authentication is the process or action of proving or showing something to be true, genuine, or valid. If we refer that to software engineering, as Oxford does too, they say it's the process or action of verifying the identity of a user or process. Or in simpler words, given by me, we want to determine whether someone or something is who or what they say they are. And as said, I will focus on the most key aspects here. And this implies that it's not a deep dive.

2. Getting Started with Authentication in Vue.js

Short description:

I want to get you started when it comes to the topic of authentication. Authn or authentication is the process of verifying the user's identity. We need to decide on three factors for authentication: something we know, something we have, or something we are. Let's think about a small code example to build a simple authentication in Vue.

I want to get you started when it comes to the topic of authentication, but I always try to refer to further resources by QR code, for example. And if you cannot screenshot it or take a picture of a QR code or scan it in time, I will share my slides later anyway. So don't be worried about that. I said I want to show you the most important parts. And this is one of those, in my cases or in my opinion.

So first things first, I want to talk about terms, because people like to mix it up, including me. So I hope I will not do this inside of this talk this time. Hopefully not. But let's be really clear on that one. Authn or authentication is the one as defined before. We want to verify who the user is and validate their identity before granting access to our features, to protected resources, whatever. And authorization of that is something different, even if they are connected.

But how can we implement such a flow in a single page application, especially as there are some differences to consider? How do we want to authenticate to the server in general? Because there are some ways, it's not only one way of authenticating, right? We need to decide on three factors which we want to use. This could be something we know like a username or password, something inside of our app. It could be something we have like a cell phone like I have here or a debit card or even a YubiKey. Something physical in most cases or something we are. Like the fingerprints we have or face ID. Those can be the points where we can authenticate, where we can prove who we are. But if we decide on those or if we think about authentication, I guess this view will come into your mind real quick, right? It's the typical login UI, having a username in it, a password in it and asking for it. So this is referring to something we know, both of those. And as it's only one factor, let's call it single factor authentication. But it doesn't need to be something we know. It can be any factor of those three mentioned before. And as it's pretty simple, let's think about a small demo, a small code example to build a simple authentication in Vue.

Check out more articles and videos

We constantly think of articles and videos that might spark Git people interest / skill us up or help building a stellar career

Everything Beyond State Management in Stores with Pinia
Vue.js London Live 2021Vue.js London Live 2021
34 min
Everything Beyond State Management in Stores with Pinia
Top Content
State management is not limited to complex applications and transitioning to a store offers significant benefits. Pinia is a centralized state management solution compatible with Vue 2 and Vue 3, providing advanced devtools support and extensibility with plugins. The core API of Pinia is similar to Vuex, but with a less verbose version of stores and powerful plugins. Pinia allows for easy state inspection, error handling, and testing. It is recommended to create one file per store for better organization and Pinia offers a more efficient performance compared to V-rex.
Welcome to Nuxt 3
Vue.js London Live 2021Vue.js London Live 2021
29 min
Welcome to Nuxt 3
Top Content
Nux3 has made significant improvements in performance, output optimization, and serverless support. Nuxt Bridge brings the Nitro engine for enhanced performance and easier transition between Nuxt 2 and Nuxt Read. Nuxt 3 supports Webpack 5, Bytes, and Vue 3. NextLab has developed brand new websites using Docus technology. Nuxt.js is recommended for building apps faster and simpler, and Nuxt 2 should be used before migrating to Nuxt 3 for stability. DOCUS is a new project that combines Nuxt with additional features like content modules and an admin panel.
One Year Into Vue 3
Vue.js London Live 2021Vue.js London Live 2021
20 min
One Year Into Vue 3
Top Content
Vue 3 has seen significant adoption and improvements in performance, bundle size, architecture, and TypeScript integration. The ecosystem around Vue 3 is catching up, with new tools and frameworks being developed. The Vue.js.org documentation is undergoing a complete overhaul. PNIA is emerging as the go-to state management solution for Vue 3. The options API and composition API are both viable options in Vue 3, with the choice depending on factors such as complexity and familiarity with TypeScript. Vue 3 continues to support CDN installation and is recommended for new projects.
Utilising Rust from Vue with WebAssembly
Vue.js London Live 2021Vue.js London Live 2021
8 min
Utilising Rust from Vue with WebAssembly
Top Content
In this Talk, the speaker demonstrates how to use Rust with WebAssembly in a Vue.js project. They explain that WebAssembly is a binary format that allows for high-performance code and less memory usage in the browser. The speaker shows how to build a Rust example using the WasmPack tool and integrate it into a Vue template. They also demonstrate how to call Rust code from a Vue component and deploy the resulting package to npm for easy sharing and consumption.
Vue: Feature Updates
Vue.js London 2023Vue.js London 2023
44 min
Vue: Feature Updates
Top Content
Watch video: Vue: Feature Updates
The Talk discusses the recent feature updates in Vue 3.3, focusing on script setup and TypeScript support. It covers improvements in defining props using imported types and complex types support. The introduction of generic components and reworked signatures for defined components provides more flexibility and better type support. Other features include automatic inference of runtime props, improved define emits and defined slots, and experimental features like reactive props destructure and define model. The Talk also mentions future plans for Vue, including stabilizing suspense and enhancing computer invalidations.
Local State and Server Cache: Finding a Balance
Vue.js London Live 2021Vue.js London Live 2021
24 min
Local State and Server Cache: Finding a Balance
Top Content
This Talk discusses handling local state in software development, particularly when dealing with asynchronous behavior and API requests. It explores the challenges of managing global state and the need for actions when handling server data. The Talk also highlights the issue of fetching data not in Vuex and the challenges of keeping data up-to-date in Vuex. It mentions alternative tools like Apollo Client and React Query for handling local state. The Talk concludes with a discussion on GitLab going public and the celebration that followed.

Workshops on related topic

Vue3: Modern Frontend App Development
Vue.js London Live 2021Vue.js London Live 2021
169 min
Vue3: Modern Frontend App Development
Top Content
Featured WorkshopFree
Mikhail Kuznetsov
Mikhail Kuznetsov
The Vue3 has been released in mid-2020. Besides many improvements and optimizations, the main feature of Vue3 brings is the Composition API – a new way to write and reuse reactive code. Let's learn more about how to use Composition API efficiently.

Besides core Vue3 features we'll explain examples of how to use popular libraries with Vue3.

Table of contents:
- Introduction to Vue3
- Composition API
- Core libraries
- Vue3 ecosystem

Prerequisites:
IDE of choice (Inellij or VSC) installed
Nodejs + NPM
Hands-On Workshop: Introduction to Pentesting for Web Apps / Web APIs
JSNation US 2024JSNation US 2024
148 min
Hands-On Workshop: Introduction to Pentesting for Web Apps / Web APIs
Featured Workshop
Gregor Biswanger
Gregor Biswanger
In this hands-on workshop, you will be equipped with the tools to effectively test the security of web applications. This course is designed for beginners as well as those already familiar with web application security testing who wish to expand their knowledge. In a world where websites play an increasingly central role, ensuring the security of these technologies is crucial. Understanding the attacker's perspective and knowing the appropriate defense mechanisms have become essential skills for IT professionals.This workshop, led by the renowned trainer Gregor Biswanger, will guide you through the use of industry-standard pentesting tools such as Burp Suite, OWASP ZAP, and the professional pentesting framework Metasploit. You will learn how to identify and exploit common vulnerabilities in web applications. Through practical exercises and challenges, you will be able to put your theoretical knowledge into practice and expand it. In this course, you will acquire the fundamental skills necessary to protect your websites from attacks and enhance the security of your systems.
API Testing with Postman Workshop
TestJS Summit 2023TestJS Summit 2023
48 min
API Testing with Postman Workshop
Top Content
WorkshopFree
Pooja Mistry
Pooja Mistry
In the ever-evolving landscape of software development, ensuring the reliability and functionality of APIs has become paramount. "API Testing with Postman" is a comprehensive workshop designed to equip participants with the knowledge and skills needed to excel in API testing using Postman, a powerful tool widely adopted by professionals in the field. This workshop delves into the fundamentals of API testing, progresses to advanced testing techniques, and explores automation, performance testing, and multi-protocol support, providing attendees with a holistic understanding of API testing with Postman.
1. Welcome to Postman- Explaining the Postman User Interface (UI)2. Workspace and Collections Collaboration- Understanding Workspaces and their role in collaboration- Exploring the concept of Collections for organizing and executing API requests3. Introduction to API Testing- Covering the basics of API testing and its significance4. Variable Management- Managing environment, global, and collection variables- Utilizing scripting snippets for dynamic data5. Building Testing Workflows- Creating effective testing workflows for comprehensive testing- Utilizing the Collection Runner for test execution- Introduction to Postbot for automated testing6. Advanced Testing- Contract Testing for ensuring API contracts- Using Mock Servers for effective testing- Maximizing productivity with Collection/Workspace templates- Integration Testing and Regression Testing strategies7. Automation with Postman- Leveraging the Postman CLI for automation- Scheduled Runs for regular testing- Integrating Postman into CI/CD pipelines8. Performance Testing- Demonstrating performance testing capabilities (showing the desktop client)- Synchronizing tests with VS Code for streamlined development9. Exploring Advanced Features - Working with Multiple Protocols: GraphQL, gRPC, and more
Join us for this workshop to unlock the full potential of Postman for API testing, streamline your testing processes, and enhance the quality and reliability of your software. Whether you're a beginner or an experienced tester, this workshop will equip you with the skills needed to excel in API testing with Postman.
Monitoring 101 for React Developers
React Summit US 2023React Summit US 2023
107 min
Monitoring 101 for React Developers
Top Content
WorkshopFree
Lazar Nikolov
Sarah Guthals
2 authors
If finding errors in your frontend project is like searching for a needle in a code haystack, then Sentry error monitoring can be your metal detector. Learn the basics of error monitoring with Sentry. Whether you are running a React, Angular, Vue, or just “vanilla” JavaScript, see how Sentry can help you find the who, what, when and where behind errors in your frontend project. 
Workshop level: Intermediate
Using Nitro – Building an App with the Latest Nuxt Rendering Engine
Vue.js London Live 2021Vue.js London Live 2021
117 min
Using Nitro – Building an App with the Latest Nuxt Rendering Engine
Top Content
Workshop
Daniel Roe
Daniel Roe
We'll build a Nuxt project together from scratch using Nitro, the new Nuxt rendering engine, and Nuxt Bridge. We'll explore some of the ways that you can use and deploy Nitro, whilst building a application together with some of the real-world constraints you'd face when deploying an app for your enterprise. Along the way, fire your questions at me and I'll do my best to answer them.
Authentication Beyond Passwords
React Day Berlin 2023React Day Berlin 2023
127 min
Authentication Beyond Passwords
WorkshopFree
Juan Cruz Martinez
Juan Cruz Martinez
Passwords have long been the keys to our kingdoms. However, they often become the weak points in our armor — forgotten, misused, or exploited. Our Next apps often make use of passwords to authenticate users, but what would a world with no passwords look like? And how we can start driving into that future today?