{"repo":"gary-archer/oauth.websample.final","free":true,"listed":false,"github":"https://github.com/gary-archer/oauth.websample.final","clone":"git clone https://github.com/gary-archer/oauth.websample.final.git","description":"Final SPA Code Sample, secured with OAuth and OpenID Connect","language":"TypeScript","stars":53,"topics":["oauth2","react","spa","typescript"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"OAuth Final SPA Overview The final demo Single Page Application, which aims to meet some Web Architecture Goals.\\ The Token Handler Pattern enables the following main behaviors: - The SPA uses the most secure cookies with no tokens in the browser, to limit the impact of XSS exploits. - The SPA uses modern productive development with only client side React technology. - The SPA static content is distributed to hundreds of locations by a CDN for best web performance. Components Cookies are managed solely by OAuth Agent and OAuth Proxy utilities on the API side of the architecture: Views The SPA is a simple UI with some basic navigation between views, to render fictional investment resources.\\ Its data is returned from an OAuth-secured API that uses claims-based authorization.\\ The SPA uses user attributes from both the OpenID Connect userinfo endpoint and its API. Online System The online version uses the AWS CloudFront content delivery network to deliver static content to the browser.\\ Login at https://www.authsamples.com/ with this AWS Cognito test account: Local Development Quick Start To run the code sample locally you must configure some infrastructure before you run the code. Configure DNS and SSL Configure custom development domains by adding this DNS entry to your hosts file: Install OpenSSL 3+ if required, create a secrets folder, then create development certificates: Finally, configure Browser SSL Trust for the SSL root certificate at this location: Run the Code Ensur","default_branch":null,"files":null,"tree":[],"storefront":"/r/gary-archer","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/gary-archer/oauth.websample.final/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}