Angled pages are single pages, singlePage Applications (or also known as a stateless architecture), the best way to authenticate in singlePage Applications is by using JWT (Json web tokens)
In case you have thought about doing the traditional method of maintaining sessions like the Httpsession of life, it makes no sense to use this in singlePageApp, as your server will only resume a single page and the rest comes dynamic vide API.
I advise you to create some webservice that returns a token and to each request that the angular do to the server you send a token next to the request payload or in the header of it, traditionally I see a lot of personnel using in the request header. Dai your webservice will check the veracity of the token passed (can be via database).
Summary:
Login request -> returns a token if successful
rest of the requests that require authentication -> takes this token in the header to a middleware or PHP authenticate method
Tip:
If you want to keep the user logged in if they give a Ctrl + r (update in the browser to page) put this token in the javascript sessionStorage, or localStorage, or $corner cookies.
I hope I helped, hug.
You may not authenticate on the routes of methods that will popular the site... That is, create separate controllers for the dashboard and for the website... in my opinion...
– rpereira15
I understand @rpereira15 , but in this case I end up leaving the GET data of the API open right? That is, since I do not need authentication to popular the data on the site, I can take the authentication of the Get routes and leave only in the POST and PUT, for example... Thank you
– Tiago Silva Pereira
It actually depends a lot on what information EVERYONE can access. In a get method for users or clients you should still have authentication...
– rpereira15
So there’s the problem, the information that I will share on the site should not be opened so that someone else can use in your application or site for example, because the API is an application, and would not like to leave this data open.
– Tiago Silva Pereira
Then stipulates a fixed token and encrypted pro site, solves the problem tb...
– rpereira15
Thank you very much man, I’ll do it. I thank you for your help
– Tiago Silva Pereira