# How Bank API Authentication and Token Handling Works in Microsoft's Web-Dev-For-Beginners

> Understand bank API authentication and token handling in Web Dev For Beginners. Learn how username lookup in localStorage simulates authentication for educational purposes.

- Repository: [Microsoft/Web-Dev-For-Beginners](https://github.com/microsoft/Web-Dev-For-Beginners)
- Tags: deep-dive
- Published: 2026-02-27

---

**The Bank API does not implement authentication or token handling; it uses a simple username lookup stored in browser localStorage for educational purposes only.**

The **Bank Project** in Microsoft's [Web-Dev-For-Beginners](https://github.com/microsoft/Web-Dev-For-Beginners) repository is designed as a learning-oriented demo to teach fundamental web development concepts. When examining how **bank API authentication and token handling** works in this codebase, you'll discover that the implementation deliberately omits production-grade security mechanisms to keep the focus on API interaction and state management.

## Server-Side Implementation (No Authentication Layer)

### In-Memory Database Structure

In [`7-bank-project/api/server.js`](https://github.com/microsoft/Web-Dev-For-Beginners/blob/main/7-bank-project/api/server.js), the Express API stores all account data in a simple in-memory JavaScript object called `db`. This object contains user records with fields like `user`, `currency`, `description`, `balance`, and `transactions`, but notably lacks any password hash or authentication credentials.

### Public API Routes

The server exposes routes such as `POST /accounts`, `GET /accounts/:user`, and `POST /accounts/:user/transactions` without any authentication middleware. As implemented in [`server.js`](https://github.com/microsoft/Web-Dev-For-Beginners/blob/main/server.js), these endpoints only verify that the requested user exists in the `db` object before returning data. CORS is enabled for localhost origins, but no token validation (such as JWT verification) occurs.

```javascript
// 7-bank-project/api/server.js
router.get('/accounts/:user', (req, res) => {
  const account = db[req.params.user];
  if (!account) return res.status(404).json({ error: 'User does not exist' });
  return res.json(account);   // No authentication token required
});

```

## Client-Side "Authentication" Flow

### Username-Only Login

In [`7-bank-project/solution/app.js`](https://github.com/microsoft/Web-Dev-For-Beginners/blob/main/7-bank-project/solution/app.js), the `login()` function handles user entry by collecting only a username from the form input. There is no password field verification or token generation step. The function calls `getAccount(user)`, which retrieves account data from **localStorage** rather than validating credentials against a secure backend.

### LocalStorage State Management

The application stores the current user data in a frozen `state` object and persists accounts using the browser's localStorage API. After a successful lookup (which only confirms the username exists), the app navigates to the dashboard. No session tokens, JWTs, or encrypted cookies are utilized throughout this process.

```javascript
// 7-bank-project/solution/app.js
async function login() {
  const form = qs('loginForm');
  if (!form.checkValidity()) return form.reportValidity();

  const user = String(form.user.value || '').trim();   // Username only
  const data = await getAccount(user);                // Reads from localStorage
  if (data.error) return updateElement('loginError', data.error);

  updateState('account', data);
  navigate('/dashboard');  // No token validation performed
}

```

## Why This Demo Skips Real Bank API Authentication

The **Web-Dev-For-Beginners** repository intentionally omits **bank API authentication and token handling** to maintain focus on core concepts like REST API design, asynchronous JavaScript, and client-side state management. Implementing JWTs, password hashing, or OAuth would introduce significant complexity that distracts from the primary learning objectives of the banking project module.

## Summary

- The Bank API uses an **in-memory object** (`db`) in [`server.js`](https://github.com/microsoft/Web-Dev-For-Beginners/blob/main/server.js) with no password fields or token generation.
- All API routes are **publicly accessible**, performing only username existence checks without authentication middleware.
- The client-side `login()` function in [`app.js`](https://github.com/microsoft/Web-Dev-For-Beginners/blob/main/app.js) validates only usernames against **localStorage**, not secure credentials.
- **No JWTs, session tokens, or encrypted cookies** are implemented in this educational demo.

## Frequently Asked Questions

### Does the Bank API use JWT tokens?

No. The Bank API in [`7-bank-project/api/server.js`](https://github.com/microsoft/Web-Dev-For-Beginners/blob/main/7-bank-project/api/server.js) does not implement JWT token generation, signing, or verification. The Express routes accept requests without any token validation, relying solely on the presence of a username in the in-memory database.

### How is user data stored in the Bank Project?

User data is stored in two locations: an **in-memory JavaScript object** (`db`) on the server that resets when the server restarts, and **localStorage** in the browser for client-side persistence. Neither storage method encrypts passwords or manages authentication tokens.

### Is the Bank Project secure for production use?

No. The Bank Project is explicitly designed as a **learning demo** and lacks essential security features including password verification, HTTPS enforcement, authentication tokens, and input sanitization. It should never be deployed to production environments handling real financial data.

### What files handle the login logic?

The client-side login logic resides in [`7-bank-project/solution/app.js`](https://github.com/microsoft/Web-Dev-For-Beginners/blob/main/7-bank-project/solution/app.js) within the `login()` and `getAccount()` functions. The server-side route handlers in [`7-bank-project/api/server.js`](https://github.com/microsoft/Web-Dev-For-Beginners/blob/main/7-bank-project/api/server.js) process account lookups but do not perform any authentication checks beyond verifying the username exists in the `db` object.