Skip to main content

Overview

The Password Generator uses JWT (JSON Web Token) authentication powered by Django REST Framework SimpleJWT. This provides secure, stateless authentication for both web and API clients.

Authentication Flow

1

User Sign-Up

New users create an account with email, username, and password. The system returns access and refresh tokens immediately upon successful registration.
2

Token Storage

The client stores the access token (short-lived) and refresh token (long-lived) securely, typically in sessionStorage or httpOnly cookies.
3

Authenticated Requests

Include the access token in the Authorization header: Bearer <token>
4

Token Refresh

When the access token expires, use the refresh token to obtain a new access token without requiring re-authentication.

Sign-Up Process

New users register through the /api/users/sign-up/ endpoint.

API Endpoint

URL: POST /api/users/sign-up/ Authentication: Not required (AllowAny) Request Body:
Response:

Implementation

The sign-up view is implemented in views.py:47-79:
The password is securely hashed using Django’s set_password() method, which uses PBKDF2 by default.

Frontend Sign-Up

The frontend implements sign-up with a React form component:

Sign-In Process

Existing users authenticate through the /api/users/sign-in/ endpoint.

API Endpoint

URL: POST /api/users/sign-in/ Authentication: Not required (AllowAny) Request Body:
Response:

Implementation

The sign-in view is implemented in views.py:21-44:

Frontend Sign-In

The sign-in implementation (SignInRequest.jsx:25-49):

Form Fields

The sign-in form includes email and password fields with NextUI Input components and validation feedback.

Token Refresh Mechanism

SimpleJWT provides automatic token refresh capabilities. When the access token expires, use the refresh token to obtain a new one.

Refresh Token Endpoint

URL: POST /api/token/refresh/ Request Body:
Response:

Token Lifecycle

Access Token

Short-lived token (typically 5-15 minutes) used for API requests

Refresh Token

Long-lived token (typically 1-7 days) used to obtain new access tokens

Client-Side Token Management

Protected Endpoints

Many endpoints require authentication using the @permission_classes([IsAuthenticated]) decorator:

Making Authenticated Requests

cURL Example:
JavaScript Example:

User Model

The custom user model extends Django’s AbstractUser (models.py:5-16):
The email field is unique and required for authentication, serving as the primary identifier for login.

Error Handling

The authentication views provide detailed error responses:

Security Best Practices

Security Recommendations:
  • Always use HTTPS in production
  • Store tokens securely (httpOnly cookies preferred over localStorage)
  • Implement token rotation strategies
  • Set appropriate token expiration times
  • Use CORS policies to restrict API access
  • Implement rate limiting on authentication endpoints
For enhanced security, consider implementing:
  • Two-factor authentication (2FA)
  • Email verification on sign-up
  • Password strength requirements
  • Account lockout after failed attempts