4 ms·
> I spent last 3 months building AngularJS + Flask where the client talks to server only through REST. I've been wanting to do something like this for a certai
by emillon 13y ago
> I spent last 3 months building AngularJS + Flask where the client talks to server only through REST.
I've been wanting to do something like this for a certain time, so I have a few questions if you don't mind.
How do you handle authentication? Tokens? Cookies? Is there a special "API key" for your web app?
- lukasm 13y agoLong story short - I went full hipster on that grunt + yeoman + bower + angular ui and my conclusion is http://i3.kym-cdn.com/photos/images/newsfeed/000/439/835/47c.jpg http://i3.kym-cdn.com/photos/images/newsfeed/000/439/835/47c... Too much complexity added to project. Going REST patch is problematic when you have to integrate with server-render style lib or service. SEO is shit. Angular doc is worse. Auth is base on tokens, no sessions. I reused the ideas from here https://github.com/mrgamer/angular-login-example https://github.com/mrgamer/angular-login-example def auth_required(f): @wraps(f) def wrapper(*args, **kwargs): token = request.headers.get("X-Token") if token is None: abort(400) user = User.verify_auth_token(token, app.config["SECRET_KEY"]) .... If you don't make very heavy SPA like photoshop, don't use angular.
- ermintrude 13y ago> Is there a special "API key" for your web app? And if there is, what's the point? Would the only reason to ever change that key be to force old clients to upgrade if the API changes?