Made it especially with you in mind. And it's free.
Section 6 & 7 - maybe this is what you are looking for?
Udemy frequently has sales on holidays and all courses are ~$15
Never understood what is so hard with user auth and why people need an example of a SPA with user auth. Your server is just a web API, so just use stateless authentication.
The reasons for these decisions would go a long way to addressing the concerns bitdeveloper has, too.
It's a React + Redux front end with Hapi + Sequelize backend. It uses JWTs in local storage for authentication (that decision will take some defending since it most applications should store it in a cookie) and sometimes uses single uses JWTs for things like email verification. I'm planning to write up how we do Google Login, password based signup and login including email verification and initial load decisions tree for dashboard or login page.
Why do you think that most application should store JWT token in the cookie? Both approaches have their pros/cons.
This does a better job that I'm going to try for in a HN comment: http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo...