Angular makes building powerful applications a breeze, but what about securing them? There are all sorts of gotchas when it comes to securing any SPA and in this talk we'll look at some best practices as we compare and contrast two different ways of talking to secure resources with our Angular application. We'll deep dive into how JSON Web Tokens make client-side security manageable and how Angular's core functionality can facilitate secure client-side applications.
CONTENTS
0:05 - Intro
0:21 - About Ado
0:55 - SPA security
1:38 - Cookie-based vs Token-based Auth
5:18 - What is JSON Web Token (JWT)
9:55 - JWT + Angular
10:43 - HTTP Client Library
11:22 - HTTP Client Library + JWT
12:47 - Interceptors
12:57 - Angular Interceptors
15:16 - Demo
23:36 - Question
RESOURCES
https://angular.io/guide/http#advanced-usage