| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Zagotavljanje zaščite pri razvoju sodobnih spletnih rešitev na osnovi standarda JWT : diplomsko delo
Authors:ID Kovačević, Nik (Author)
ID Šumak, Boštjan (Mentor) More about this mentor... New window
Files:.pdf UN_Kovacevic_Nik_2022.pdf (1,57 MB)
MD5: 4405CA21A5D9B14F9372D52170424F47
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FERI - Faculty of Electrical Engineering and Computer Science
Abstract:V razvoju sodobnih spletnih rešitev se soočamo s problemom avtentikacije, ki se zaradi možnosti skalabilnosti iz strežniške strani seli na odjemalčevo stran. Zato smo v diplomski nalogi predstavili način zagotavljanja zaščite sodobnih spletnih rešitev z uporabo identifikacijskih žetonov JWT (JSON Web Token). To je standard za varen prenos informacij med dvema sodelujočima, običajno sta to strežnik in odjemalec. V nalogi smo implementirali avtentikacijo in avtorizacijo uporabnikov v spletno rešitev, ki je temeljila na izvajalnem okolju Node.js, z uporabo žetonov JWS (JSON Web Signature). Ogledali smo si tudi alternative za standard JWT, to so žetoni Fernet, Branca in PASETO, ki popravljajo ranljivosti in slabosti JWT. Razvijalsko skupnost smo povprašali, katere izmed zgoraj naštetih identifikacijskih žetonov uporabljajo. Ugotavljamo, da se velika večina odloča za JWT, saj so alternative dokaj nepoznane in nestandardizirane. Alternative žetona JWT še niso pripravljene zamenjati, lahko pa ga pomagajo nadgraditi in zmanjšati njegove slabosti.
Keywords:varnost, JWT, identifikacijski žetoni, Express.js, Node.js
Place of publishing:Maribor
Place of performance:Maribor
Publisher:[N. Kovačević]
Year of publishing:2022
Number of pages:1 spletni vir (1 datoteka PDF (XII, 60 f.))
PID:20.500.12556/DKUM-82718 New window
UDC:004.77.056(043.2)
COBISS.SI-ID:133585667 New window
Publication date in DKUM:21.10.2022
Views:885
Downloads:53
Metadata:XML DC-XML DC-RDF
Categories:KTFMB - FERI
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-SA 4.0, Creative Commons Attribution-ShareAlike 4.0 International
Link:http://creativecommons.org/licenses/by-sa/4.0/
Description:This Creative Commons license is very similar to the regular Attribution license, but requires the release of all derivative works under this same license.
Licensing start date:30.08.2022

Secondary language

Language:English
Title:Ensuring Security in Modern Web Development Using JWT Standard
Abstract:In modern web development we face an issue that is authentication, which is migrating from server-side to client-side, so web solutions stay scalable. Which is why in our thesis, we present identification tokens called JWT (JSON Web Token) that ensure security in modern web applications. JWT is a standard for safely passing claim in space constrained environments, usually between a server and a client. In our thesis we have implemented user authentication and authorization in our Node.JS web solution with the usage of JWS (JSON Web Signature) tokens. We will also review some alternatives for JWTs. These are Fernet, Branca and PASETO tokens, which are supposed to fix JWT vulnerabilities. We asked the web development community which identification tokens they use. We found out, that the vast majority of the community goes for JWT as their token, as the alternatives are fairly unknown and are not standardized. The JWT alternatives are not ready to take JWTs place, but they can help upgrade it and solve its issues
Keywords:security, JWT, identification token, Express.js, Node.js


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica