Authentication & Security — MERN Stack Roadmap
Securing a MERN application end to end
Steps in Authentication & Security
- Authentication Basics — advanced · Sessions vs tokens and the general authentication flow
- JWT Authentication — advanced · Issuing, verifying and refreshing JSON Web Tokens
- Password Hashing (bcrypt) — advanced · Why plaintext passwords are unsafe and how bcrypt hashing works
- OAuth & Social Login — advanced · Adding Google/GitHub login using OAuth2
- Role-Based Access Control — advanced · Restricting routes and actions based on user roles
- Securing Express Apps — advanced · Helmet, rate limiting, input sanitization and preventing common attacks (XSS, NoSQL injection)
- Protecting React Routes — advanced · Guarding frontend routes based on auth state and token expiry
Part of
- MERN Stack roadmap — the full learning path