Skip to main content

How would you implement protected routes that require user authentication?

Implementing protected routes—where access is restricted to authenticated users—is a common requirement in modern web apps to guard sensitive pages or features.

Here’s a general approach and examples for React Router and Angular Router on how to implement protected routes that check if a user is authenticated before allowing access:

How would you implement protected routes that require user authentication?

πŸ›‘️ Conceptual Overview

  1. Authentication Check: Before rendering the protected component, check if the user is logged in (e.g., via a token, session, or auth context).

  2. Conditional Rendering or Redirection:

    • If authenticated, allow access (render the component).

    • If not, redirect to a login page or show an unauthorized message.

  3. Persist Authentication State: Use global state, context, or a service to store auth status.

✅ React Router Example

Step 1: Create a ProtectedRoute component

import { Navigate } from 'react-router-dom'; function ProtectedRoute({ isAuthenticated, children }) { if (!isAuthenticated) { // Redirect to login if not authenticated return <Navigate to="/login" replace />; } // Render the protected component if authenticated return children; }

Step 2: Use ProtectedRoute in your routing setup

import { Routes, Route } from 'react-router-dom'; function App() { const isAuthenticated = /* get from context or state, e.g. */ true; return ( <Routes> <Route path="/login" element={<LoginPage />} /> <Route path="/dashboard" element={ <ProtectedRoute isAuthenticated={isAuthenticated}> <Dashboard /> </ProtectedRoute> } /> </Routes> ); }

✅ Angular Router Example

Step 1: Create an Auth Guard

import { Injectable } from '@angular/core'; import { CanActivate, Router } from '@angular/router'; import { AuthService } from './auth.service'; // your auth logic @Injectable({ providedIn: 'root', }) export class AuthGuard implements CanActivate { constructor(private authService: AuthService, private router: Router) {} canActivate(): boolean { if (this.authService.isLoggedIn()) { return true; // Allow access } else { this.router.navigate(['/login']); // Redirect if not authenticated return false; } } }

Step 2: Apply the guard to routes

const routes: Routes = [ { path: 'login', component: LoginComponent }, { path: 'dashboard', component: DashboardComponent, canActivate: [AuthGuard], }, ];

🧠 Key Points

  • Centralize auth state: Use context (React) or services (Angular) to hold auth info.

  • Redirects: Always redirect unauthenticated users to login or an error page.

  • Flexible guards: You can extend auth guards to check roles or permissions.

  • Persist auth: Use cookies, localStorage, or secure tokens to persist sessions.

Popular posts from this blog

How does BGP prevent routing loops? Explain AS_PATH and loop prevention mechanisms.

 In Border Gateway Protocol (BGP), preventing routing loops is critical — especially because BGP is the inter-domain routing protocol used to connect Autonomous Systems (ASes) on the internet. πŸ”„ How BGP Prevents Routing Loops The main mechanism BGP uses is the AS_PATH attribute . πŸ” What is AS_PATH? AS_PATH is a BGP path attribute that lists the sequence of Autonomous Systems (AS numbers) a route has traversed. Each time a route is advertised across an AS boundary, the local AS number is prepended to the AS_PATH. Example: If AS 65001 → AS 65002 → AS 65003 is the route a prefix has taken, the AS_PATH will look like: makefile AS_PATH: 65003 65002 65001 It’s prepended in reverse order — so the last AS is first . 🚫 Loop Prevention Using AS_PATH ✅ Core Mechanism: BGP routers reject any route advertisement that contains their own AS number in the AS_PATH. πŸ” Why It Works: If a route makes its way back to an AS that’s already in the AS_PATH , that AS kno...

What are the different types of directives in Angular? Give real-world examples.

In Angular, directives are classes that allow you to manipulate the DOM or component behavior . There are three main types of directives: 🧱 1. Component Directives Technically, components are directives with a template. They control a section of the screen (UI) and encapsulate logi c. ✅ Example: @Component ({ selector : 'app-user-card' , template : `<h2>{{ name }}</h2>` }) export class UserCardComponent { name = 'Alice' ; } πŸ“Œ Real-World Use: A ProductCardComponent showing product details on an e-commerce site. A ChatMessageComponent displaying individual messages in a chat app. ⚙️ 2. Structural Directives These change the DOM layout by adding or removing elements. ✅ Built-in Examples: *ngIf : Conditionally includes a template. *ngFor : Iterates over a list and renders template for each item. *ngSwitch : Switches views based on a condition. πŸ“Œ Real-World Use: < div * ngIf = "user.isLoggedIn...

Explain the Angular compilation process: View Engine vs. Ivy.

 The Angular compilation process transforms your Angular templates and components into efficient JavaScript code that the browser can execute. Over time, Angular has evolved from the View Engine compiler to a newer, more efficient system called Ivy . Here's a breakdown of the differences between View Engine and Ivy , and how each affects the compilation process: πŸ”§ 1. What Is Angular Compilation? Angular templates ( HTML inside components) are not regular HTML—they include Angular-specific syntax like *ngIf , {{ }} interpolation, and custom directives. The compiler translates these templates into JavaScript instructions that render and update the DOM. Angular uses Ahead-of-Time (AOT) or Just-in-Time (JIT) compilation modes: JIT : Compiles in the browser at runtime (used in development). AOT : Compiles at build time into efficient JS (used in production). 🧱 2. View Engine (Legacy Compiler) ➤ Used in Angular versions < 9 πŸ” How It Works: Compiles templat...