For those of you who've built authentication from scratch in a JavaScript/Node.js application, what part of the implementation gave you the most trouble—not the theory, but the actual engineering? Was it things like session management, refresh tokens, email verification, password recovery, MFA, OAuth, rate limiting, preventing account enumeration, securely handling tokens, or simply keeping all the pieces working together?
For further actions, you may consider blocking this person and/or reporting abuse
Top comments (0)