Opensesame

Simple authentication and user management service.

OpenSesame

A self-built authentication and user-management service, with roles and permissions baked in.

Live app · Frontend source · Backend source

Every product eventually needs to answer “who is this user, and what are they allowed to do.” Instead of reaching for a third-party auth provider, I built that piece myself: a JWT-based auth API paired with an admin console to manage users, roles, and fine-grained permissions.

What it does

  • Log in / log out with JWT issued as httpOnly cookies — no tokens sitting in localStorage
  • Two-layer access control: coarse admin / user roles plus per-user granular permissions
  • Admin console to list, search, and inspect users
  • Admins provision new accounts, force password resets, and grant or revoke roles/permissions
  • Users can change their own password once logged in

OpenSesame login screen

OpenSesame admin console

OpenSesame new user console

How it’s built

React 19 + TypeScript frontend (React Router v7, Context-based state, Axios over cookie auth) talking to a Node/Express + TypeScript API backed by MongoDB. The API is hardened with helmet, CORS allow-listing, rate limiting, request validation, and bcrypt password hashing.

  • One-command full-stack demo — a Docker Compose stack spins up MongoDB, the auth API, and the frontend together, seeded with a demo admin user, so anyone can try the whole thing locally in minutes.
  • CI & security gate — every push and PR runs a full verify pipeline (audit, lint, typecheck, test, build) across both repos, plus gitleaks secret scanning before anything merges.

Try the live app, or spin up the Docker demo yourself.