mirror of
https://github.com/sasjs/server.git
synced 2026-07-23 13:15:29 +00:00
398dfb515c
Add a new diagram covering the authentication mechanism: a session-based /SASLogon/login + /SASLogon/authorize handshake that mints a short-lived auth code, exchanged at /SASjsApi/auth/token for a revocable JWT pair, with optional LDAP-backed credential verification. Add WHY comments (not present before) at the handful of spots in the auth code whose behaviour isn't obvious from reading them in isolation: why /auth/token can return an existing token pair instead of rotating it, why the auth-code exchange never checks a client's clientSecret, how verifyTokenInDB turns self-verifying JWTs into revocable ones, why two /SASjsApi/user routes stay reachable in desktop mode, why the static authorized-route list exists on top of plain authentication, and why /SASjsApi/client's real protection lives at its router mount point in routes/api/index.ts rather than in client.ts itself.