{"id":95617,"date":"2022-07-26T22:43:03","date_gmt":"2022-07-26T20:43:03","guid":{"rendered":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/"},"modified":"2020-12-04T17:22:56","modified_gmt":"2020-12-04T20:22:56","slug":"metodos-de-autenticacion-web-explicados","status":"publish","type":"post","link":"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/","title":{"rendered":"Web authentication methods explained"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewbox=\"0 0 24 24\" version=\"1.2\" baseprofile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#Autenticacion-basica-HTTP\" >HTTP basic authentication<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#Cookies\" >cookies<\/a><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#Siempre-use-las-cookies-de-HttpOnly\" >Always use HttpOnly cookies<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#Siempre-usa-cookies-firmadas\" >Always use signed cookies<\/a><ul class='ez-toc-list-level-5' ><li class='ez-toc-heading-level-5'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#Uso-de-cookies-de-Chrome\" >Use of Chrome cookies<\/a><\/li><\/ul><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#Fichas\" >Records<\/a><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#Firmas\" >Firms<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#Contrasenas-de-un-solo-uso\" >One-time passwords<\/a><ul class='ez-toc-list-level-5' ><li class='ez-toc-heading-level-5'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/#%C2%BFQue-metodo-de-autenticacion-web-elegir-cuando\" >Which web authentication method to choose when?<\/a><\/li><\/ul><\/li><\/ul><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<div itemprop=\"articleBody\">\n<p>In today&#039;s lesson we are going to start with the most basic, basic HTTP authentication, continue with cookies and tokens, and end with one-time signatures and passwords. Read on to learn all about this.<span id=\"more-144\"\/><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Autenticacion-basica-HTTP\"><\/span>HTTP basic authentication<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The <strong>HTTP authentication <\/strong>basic is a method for the customer to provide a username and password when making a request.<\/p>\n<p>This is the simplest possible way to enforce access control, as it does not require cookies, sessions, or anything else. To use this, the client must send the <em>Authorization<\/em> along with every request you make. The name of <strong>Username<\/strong> and the <strong>password<\/strong> they are not encrypted, but they are constructed like this:<\/p>\n<p>The username and password are concatenated into a single string: <strong>username: password\u00a0<\/strong>this string is Base64 encoded<\/p>\n<p>The key word\u00a0<em>BASIC<\/em> is placed before this hardcoded value<\/p>\n<p>Example for a user named juan with a secret password:<\/p>\n<pre data-enlighter-language=\"php\" class=\"EnlighterJSRAW\">curl --header &quot;Authorization: Basic am9objpzZWNyZXQ =&quot; my-website.com\n<\/pre>\n<p>Implementing it is pretty easy in Node.js too - the following code snippet shows how you can make a <strong>Express middleware<\/strong> to do it.<\/p>\n<pre data-enlighter-language=\"php\" class=\"EnlighterJSRAW\">&#13;\nimport basicAuth from 'basic-auth';&#13;\n&#13;\nfunction unauthorized(res) {&#13;\nres.set('WWW-Authenticate', 'Basic realm=Authorization Required');&#13;\nreturn res.send(401);&#13;\n};&#13;\n&#13;\nexport default function auth(req, res, next) {&#13;\nconst {name, pass} = basicAuth(req) || {};&#13;\n&#13;\nif (!name || !pass) {&#13;\nreturn unauthorized(res);&#13;\n};&#13;\n&#13;\nif (name === 'juan' &amp;&amp; pass === 'secreta') {&#13;\nreturn next();&#13;\n}&#13;\nreturn unauthorized(res);&#13;\n};&#13;\n<\/pre>\n<p>Of course, you can do it at a higher level, like in nginx.<\/p>\n<p>Sounds simple, right? So what are the downsides of using HTTP Basic Authentication?<\/p>\n<p>The cons:<\/p>\n<ul>\n<li>The username and password are sent with every request, potentially exposing them, even if they are sent over a secure connection connected to <em>SSL \/ TLS<\/em>, if a website uses weak encryption or an attacker can break it,<\/li>\n<li>Usernames and passwords will be exposed immediately there is no way to log out the user using basic authentication, the expiration of credentials is not trivial - you have to ask the user to change the password to do so.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Cookies\"><\/span>cookies<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>When a server receives an HTTP request in the response, it can send a header <em>Set-Cookie.<\/em> The browser places it in a cookie container, and the cookie will be sent along with each request made to the same origin in the HTTP Cookie header.<\/p>\n<p>To use cookies for authentication purposes, there are a few key principles that must be followed.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Siempre-use-las-cookies-de-HttpOnly\"><\/span>Always use HttpOnly cookies<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>To mitigate the possibility of XSS attacks, always use the flag <strong>HttpOnly<\/strong> when setting cookies. This way they will not appear in <strong>document.cookies.<\/strong><\/p>\n<h4><span class=\"ez-toc-section\" id=\"Siempre-usa-cookies-firmadas\"><\/span>Always use signed cookies<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>With signed cookies, a server can tell if the client modified a cookie.<\/p>\n<p>Later, all requests use the cookies set for the given domain:<\/p>\n<h5><span class=\"ez-toc-section\" id=\"Uso-de-cookies-de-Chrome\"><\/span>Use of Chrome cookies<span class=\"ez-toc-section-end\"><\/span><\/h5>\n<p>The cons:<\/p>\n<ul>\n<li>Need to go the extra mile to mitigate CSRF attacks<\/li>\n<li>Incompatibility with REST as it introduces a state into a stateless protocol<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Fichas\"><\/span>Records<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Today, JWT (JSON Web Token) is everywhere; the potential security issues are worth a look though.<\/p>\n<p>JWT consists of three parts:<\/p>\n<ul>\n<li><strong>Header:<\/strong> containing the token type and hashing algorithm<\/li>\n<li><strong>Useful load:<\/strong> containing the claims.<\/li>\n<li><strong>Firm:<\/strong> which can be calculated as follows if you choose HMAC SHA256: HMACSHA256 (base64UrlEncode (header) + &quot;.&quot; + base64UrlEncode (payload), secret)<\/li>\n<\/ul>\n<p>Add <strong>JWT<\/strong> to applications <strong>Koa<\/strong> it&#039;s just a couple of lines of code:<\/p>\n<pre data-enlighter-language=\"php\" class=\"EnlighterJSRAW\">var koa = require (&#039;koa&#039;); var jwt = require (&#039;koa-jwt&#039;); var app = koa (); app.use (jwt ({secret: &#039;very-secret&#039;})); \/\/ Protected middleware app.use (function * () {\/\/ the content of the token will be available in this.state.user this.body = {secret: &#039;42&#039;};});\n<\/pre>\n<p>Example of use:<\/p>\n<pre data-enlighter-language=\"php\" class=\"EnlighterJSRAW\">curl --header &quot;Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRJONYQDXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiOWRJONYQRG9lIiwiYWRJONW4OrZOrZBrsiteBuyWRJONW4GRG9lIiwiYWRJONY7MyGsiteBuyByWRtaW4GRG9lIiwiYWRJONW4OrZOrZSiteBuyWRTaW4gRG9lIiwiYWRJONW4OrZOrZSiWo9WRTaW4Gsite\n<\/pre>\n<p>Like the previous ones, the tokens can also be observed in Chrome:<\/p>\n<p>If you are writing API for native mobile apps or SPA, JWT may be a good choice for you. One thing to note: to use JWT in the browser, you have to store it in <strong>LocalStorage<\/strong> or <strong>SessionStorage,<\/strong> which can lead to XSS attacks.<\/p>\n<p>The cons:<\/p>\n<ul>\n<li>Need to go the extra mile to mitigate XSS attacks<\/li>\n<\/ul>\n<h4><span class=\"ez-toc-section\" id=\"Firmas\"><\/span>Firms<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Whether using cookies or tokens, if the transport layer is exposed for any reason, your credentials are easy to access, and with a token or cookie the attacker can act like the real user.<\/p>\n<p>One possible way to solve this, at least when it comes to the API and not the browser, is to sign every request. How can we do it?<\/p>\n<p>When a consumer of an API makes a request, they must sign it, which means they must create a <em>hash<\/em> of the entire request using a private key. For that hash calculation you can use:<\/p>\n<ul>\n<li>HTTP method<\/li>\n<li>Request path<\/li>\n<li>HTTP headers<\/li>\n<li>HTTP payload checksum<\/li>\n<li>and a private key to create the hash<\/li>\n<\/ul>\n<p>For this to work, both the API consumer and the provider must have the same private key. Once you have the signature, you need to add it to the request, either in query strings or HTTP headers. In addition, a date must also be added, so that you can define an expiration date.<\/p>\n<p>Why go through all these steps? Because even if the transport layer is compromised, an attacker can only read your traffic, he will not be able to act as a user, since the attacker will not be able to sign requests, since the private key is not in his possession. Most AWS services are using this type of authentication.<\/p>\n<p><strong>node-http-signature<\/strong> deals with HTTP request signing and is worth checking out.<\/p>\n<p>The cons:<\/p>\n<ul>\n<li>Cannot be used in browser \/ client, only between APIs<\/li>\n<\/ul>\n<h4><span class=\"ez-toc-section\" id=\"Contrasenas-de-un-solo-uso\"><\/span>One-time passwords<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>One-time password algorithms generate a one-time password with a shared secret and the current time or counter:<\/p>\n<ul>\n<li>One-time password algorithm <strong>time based<\/strong>, is based on the current time.<\/li>\n<li>One-time password algorithm <strong>based on HMAC<\/strong>, is based on a counter.<\/li>\n<\/ul>\n<p>These methods are used in applications that take advantage of two-factor authentication: a user enters the username and password, and both the server and the client generate a one-time password.<\/p>\n<p>In Node.js, implement this using <strong>notp<\/strong> it is relatively easy.<\/p>\n<p>Cons:<\/p>\n<ul>\n<li>With shared secret user tokens (if stolen) they can be emulated<\/li>\n<li>because clients can be stolen, all real-time applications have methods to avoid this, such as an email reset that adds additional attack vectors to the application<\/li>\n<\/ul>\n<h5><span class=\"ez-toc-section\" id=\"%C2%BFQue-metodo-de-autenticacion-web-elegir-cuando\"><\/span>Which web authentication method to choose when?<span class=\"ez-toc-section-end\"><\/span><\/h5>\n<p>If you only have to support one web application, cookies or tokens are fine. For cookies, think of XSRF, so JWT takes care of XSS.<\/p>\n<p>If you have to support a web app and mobile client, use an API that supports token-based authentication.<\/p>\n<p>If you are creating APIs that communicate with each other, better use request signing.<\/p>\n<\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>En la lecci\u00f3n de hoy vamos a comenzar con la m\u00e1s b\u00e1sica, la autenticaci\u00f3n HTTP b\u00e1sica, continuaremos con las cookies y los tokens , y terminaremos con firmas y contrase\u00f1as&#8230;<\/p>","protected":false},"author":1,"featured_media":95618,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1374],"tags":[],"class_list":["post-95617","post","type-post","status-publish","format-standard","has-post-thumbnail","category-javascript"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v28.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>M\u00e9todos de autenticaci\u00f3n web explicados - R Marketing Digital<\/title>\n<meta name=\"description\" content=\"En la lecci\u00f3n de hoy vamos a comenzar con la m\u00e1s b\u00e1sica, la autenticaci\u00f3n HTTP b\u00e1sica, continuaremos con las cookies y los tokens , y terminaremos con\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"M\u00e9todos de autenticaci\u00f3n web explicados\" \/>\n<meta property=\"og:description\" content=\"En la lecci\u00f3n de hoy vamos a comenzar con la m\u00e1s b\u00e1sica, la autenticaci\u00f3n HTTP b\u00e1sica, continuaremos con las cookies y los tokens , y terminaremos con\" \/>\n<meta property=\"og:url\" content=\"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/\" \/>\n<meta property=\"og:site_name\" content=\"R Marketing Digital\" \/>\n<meta property=\"article:published_time\" content=\"2022-07-26T20:43:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/rmarketingdigital.com\/wp-content\/uploads\/2020\/12\/fotolia_902094_XS-7117224.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"375\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"R Marketing Digital\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/\"},\"author\":{\"name\":\"R Marketing Digital\",\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/#\\\/schema\\\/person\\\/7c0d9782b2977b840b3740f00c69a73e\"},\"headline\":\"M\u00e9todos de autenticaci\u00f3n web explicados\",\"datePublished\":\"2022-07-26T20:43:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/\"},\"wordCount\":1171,\"image\":{\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rmarketingdigital.com\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/fotolia_902094_XS-7117224.jpg\",\"articleSection\":[\"Javascript\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/\",\"url\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/\",\"name\":\"M\u00e9todos de autenticaci\u00f3n web explicados - R Marketing Digital\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rmarketingdigital.com\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/fotolia_902094_XS-7117224.jpg\",\"datePublished\":\"2022-07-26T20:43:03+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/#\\\/schema\\\/person\\\/7c0d9782b2977b840b3740f00c69a73e\"},\"description\":\"En la lecci\u00f3n de hoy vamos a comenzar con la m\u00e1s b\u00e1sica, la autenticaci\u00f3n HTTP b\u00e1sica, continuaremos con las cookies y los tokens , y terminaremos con\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/javascript\\\/metodos-de-autenticacion-web-explicados\\\/#primaryimage\",\"url\":\"https:\\\/\\\/rmarketingdigital.com\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/fotolia_902094_XS-7117224.jpg\",\"contentUrl\":\"https:\\\/\\\/rmarketingdigital.com\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/fotolia_902094_XS-7117224.jpg\",\"width\":600,\"height\":375,\"caption\":\"fotolia_902094_xs-7117224-3090328-jpg\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/#website\",\"url\":\"https:\\\/\\\/rmarketingdigital.com\\\/\",\"name\":\"R Marketing Digital\",\"description\":\"Agencia SEO | Publicidad redes sociales | Community Management\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/rmarketingdigital.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/rmarketingdigital.com\\\/#\\\/schema\\\/person\\\/7c0d9782b2977b840b3740f00c69a73e\",\"name\":\"R Marketing Digital\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c5599c203e0120b8ccbff4666af86f35f9b3dcad468a8bc6295313a3964a80be?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c5599c203e0120b8ccbff4666af86f35f9b3dcad468a8bc6295313a3964a80be?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c5599c203e0120b8ccbff4666af86f35f9b3dcad468a8bc6295313a3964a80be?s=96&d=mm&r=g\",\"caption\":\"R Marketing Digital\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"M\u00e9todos de autenticaci\u00f3n web explicados - R Marketing Digital","description":"In today&#039;s lesson we are going to start with the most basic, basic HTTP authentication, we will continue with cookies and tokens, and we will end with","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/","og_locale":"en_US","og_type":"article","og_title":"M\u00e9todos de autenticaci\u00f3n web explicados","og_description":"En la lecci\u00f3n de hoy vamos a comenzar con la m\u00e1s b\u00e1sica, la autenticaci\u00f3n HTTP b\u00e1sica, continuaremos con las cookies y los tokens , y terminaremos con","og_url":"https:\/\/rmarketingdigital.com\/en\/javascript\/metodos-de-autenticacion-web-explicados\/","og_site_name":"R Marketing Digital","article_published_time":"2022-07-26T20:43:03+00:00","og_image":[{"width":600,"height":375,"url":"https:\/\/rmarketingdigital.com\/wp-content\/uploads\/2020\/12\/fotolia_902094_XS-7117224.jpg","type":"image\/jpeg"}],"author":"R Marketing Digital","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/#article","isPartOf":{"@id":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/"},"author":{"name":"R Marketing Digital","@id":"https:\/\/rmarketingdigital.com\/#\/schema\/person\/7c0d9782b2977b840b3740f00c69a73e"},"headline":"M\u00e9todos de autenticaci\u00f3n web explicados","datePublished":"2022-07-26T20:43:03+00:00","mainEntityOfPage":{"@id":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/"},"wordCount":1171,"image":{"@id":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/#primaryimage"},"thumbnailUrl":"https:\/\/rmarketingdigital.com\/wp-content\/uploads\/2020\/12\/fotolia_902094_XS-7117224.jpg","articleSection":["Javascript"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/","url":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/","name":"M\u00e9todos de autenticaci\u00f3n web explicados - R Marketing Digital","isPartOf":{"@id":"https:\/\/rmarketingdigital.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/#primaryimage"},"image":{"@id":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/#primaryimage"},"thumbnailUrl":"https:\/\/rmarketingdigital.com\/wp-content\/uploads\/2020\/12\/fotolia_902094_XS-7117224.jpg","datePublished":"2022-07-26T20:43:03+00:00","author":{"@id":"https:\/\/rmarketingdigital.com\/#\/schema\/person\/7c0d9782b2977b840b3740f00c69a73e"},"description":"In today&#039;s lesson we are going to start with the most basic, basic HTTP authentication, we will continue with cookies and tokens, and we will end with","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/rmarketingdigital.com\/javascript\/metodos-de-autenticacion-web-explicados\/#primaryimage","url":"https:\/\/rmarketingdigital.com\/wp-content\/uploads\/2020\/12\/fotolia_902094_XS-7117224.jpg","contentUrl":"https:\/\/rmarketingdigital.com\/wp-content\/uploads\/2020\/12\/fotolia_902094_XS-7117224.jpg","width":600,"height":375,"caption":"fotolia_902094_xs-7117224-3090328-jpg"},{"@type":"WebSite","@id":"https:\/\/rmarketingdigital.com\/#website","url":"https:\/\/rmarketingdigital.com\/","name":"R Digital Marketing","description":"SEO Agency | Advertising social networks | Community Management","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/rmarketingdigital.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/rmarketingdigital.com\/#\/schema\/person\/7c0d9782b2977b840b3740f00c69a73e","name":"R Digital Marketing","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c5599c203e0120b8ccbff4666af86f35f9b3dcad468a8bc6295313a3964a80be?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/c5599c203e0120b8ccbff4666af86f35f9b3dcad468a8bc6295313a3964a80be?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c5599c203e0120b8ccbff4666af86f35f9b3dcad468a8bc6295313a3964a80be?s=96&d=mm&r=g","caption":"R Marketing Digital"}}]}},"_links":{"self":[{"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/posts\/95617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/comments?post=95617"}],"version-history":[{"count":0,"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/posts\/95617\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/media\/95618"}],"wp:attachment":[{"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/media?parent=95617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/categories?post=95617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rmarketingdigital.com\/en\/wp-json\/wp\/v2\/tags?post=95617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}