{"repo":"gary-archer/oauth.apisample.serverless","free":true,"listed":false,"github":"https://github.com/gary-archer/oauth.apisample.serverless","clone":"git clone https://github.com/gary-archer/oauth.apisample.serverless.git","description":"Final OAuth secured Serverless API Code Sample","language":"TypeScript","stars":13,"topics":["api","nodejs","oauth2","serverless","typescript"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Final Serverless API The Serverless OAuth secured Node.js API code sample: - The API users a zero trust approach and does its own JWT access token validation. - The API takes control over OAuth claims-based authorization to enable security with good manageability. - The API uses JSON request logging and can use log aggregation, for the best supportability. API Serves Frontend Clients The API can run as part of an OAuth end-to-end setup, to serve my blog's UI code samples.\\ Running the API in this manner forces it to be consumer-focused to its clients: The AWS deployed API is the default API that the blog's final frontend code samples connect to: - Final Single Page Application - Final Desktop App - Final iOS App - Final Android App API Security is Testable The API's clients are UIs, which get user-level access tokens by running an OpenID Connect code flow.\\ To enable test-driven development, the API instead mocks the authorization server: A basic load test fires batches of concurrent requests at the API.\\ This further verifies reliability and the correctness of API logs. API is Supportable You can aggregate request logs and audit logs to Elasticsearch and run Technical Support Queries. Local Development Quick Start To run the code sample locally you must configure some infrastructure before you run the code. Configure DNS and SSL Configure custom development domains by adding these DNS entries to your hosts file: Install OpenSSL 3+ if required, create a secrets folder, then c","default_branch":null,"files":null,"tree":[],"storefront":"/r/gary-archer","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/gary-archer/oauth.apisample.serverless/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}