Hardening Single Page Application Security

Presented by

Michal Trojanowski, Product Marketing Engineer, Gary Archer Product Marketing Engineer at Curity

About this talk

When it comes to user experience and infrastructure management, Single Page Applications (SPA) are great, but securing them can be difficult. Since SPAs require access tokens to call APIs, it is challenging to store these in the browser securely. The solution to this problem is an advancement of the common Backend for Frontend (BFF) design pattern. In this expanded form, called the Token Handler, the lightweight back-end component simplifies the security of the SPA using a BFF to ease the OAuth integration. The Token Handler, a BFF for OAuth and SPAs, is an architecture where web applications transfer the handling of OAuth to a utility API. This trusted agent is able to perform more secure interactions with the OAuth authorization server and store access tokens in a safe manner. It exposes these to the SPA using robust browser security techniques. Using the Token Handler pattern maintains the usability and deployment benefits of a SPA architecture without compromising security. In this webinar, we discuss challenges confronting SPAs developers and operators, how OAuth can be used correctly and incorrectly in SPAs, and how these challenges and errors can be overcome using the Token Handler pattern.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (13)
Subscribers (644)
Curity is a leading provider of IAM and API security technology that enables user authentication and authorization for a wide range of digital services. The Curity Identity Server is highly scalable, and handles the complexities of the leading identity standards, making them easier to use, customize and deploy. Today, the Curity Identity Server is the most complete OAuth and OpenID Connect server, and we enjoy the trust of large organizations in most industries, including financial services, telecom, retail, gaming, energy, and government services across many countries.