Home Projects Portfolio Dashboard Export PDF Log in

Securing Beauty-Appointment-System: Implementing JWT Authentication and Role-Based Access Control

Securing an application is often the most critical step in moving from a functional prototype to a production-ready service. In the SBSofiaBartoli/beauty-appointment-system, we reached a point where basic API access was no longer sufficient. We needed to ensure that users were who they claimed to be and that they only performed actions permitted by their specific roles.

The Security Gap

Previously, our Express backend served endpoints without verifying user identity or permission levels. While this allowed for rapid development of appointment features, it posed significant risks regarding data exposure and unauthorized modification of scheduling records. We needed a strategy that integrated seamlessly with our existing TypeORM-based hexagonal architecture.

The Implementation Strategy

We decided to leverage JSON Web Tokens (JWT) for stateless authentication. By moving logic into reusable middleware, we ensured that our route handlers remained clean and focused purely on business logic rather than security boilerplate.

Protecting Routes with Middleware

We implemented a custom middleware function that validates the token and attaches the user's role to the request object. Here is how we structure that validation layer:

import { Request, Response, NextFunction } from 'express';
import jwt from 'jsonwebtoken';

export const authenticate = (req: Request, res: Response, next: NextFunction) => {
  const token = req.headers.authorization?.split(' ')[1];
  if (!token) return res.status(401).json({ message: 'Unauthorized' });

  try {
    const decoded = jwt.verify(token, process.env.JWT_SECRET);
    req.user = decoded;
    next();
  } catch (err) {
    res.status(403).json({ message: 'Invalid token' });
  }
};

We extended this by creating a role-check wrapper, which allows us to restrict specific endpoints, such as administrative dashboards or appointment management utilities, to authorized personnel only.

Integrating with the Repository Pattern

Since our system utilizes the Repository Pattern, we kept the security layer decoupled from our data access layer. The controllers now check the user's claims before calling the Repository methods. This separation ensures that even if a developer forgets to add a check, the core business entities remain protected by the centralized authentication gate.

Key Takeaways

  1. Middleware as a Gatekeeper: Always handle authentication in the middleware layer to keep your route controllers thin.
  2. Stateless Scalability: Using JWT allows our API to remain scalable without needing to manage session state on the server side.
  3. Granular Control: Role-based access ensures that 'customer' accounts cannot access 'admin' functionality, protecting critical appointment system operations.

Next time you find yourself securing a new feature, start by defining your roles clearly and wrapping your routes in standard authentication middleware before writing a single line of business logic.


Generated with Gitvlg.com

Securing Beauty-Appointment-System: Implementing JWT Authentication and Role-Based Access Control
SOFIA DESIREE BARTOLI

SOFIA DESIREE BARTOLI

Author

Share: