Angular Route Guards — Interview Quick Revision
1. What is a route guard?
A route guard controls whether a user can access, leave, or match an Angular route.
It is commonly used for authentication, authorization, and unsaved-change checks.
2. Why do we need route guards?
Route guards prevent users from navigating to routes they should not access.
Example: prevent an unauthenticated user from opening /admin.
3. What is an authentication guard?
An authentication guard checks whether the user is logged in/authenticated before allowing route navigation.
Example: check whether a valid login/session exists.
4. What is an authorization guard?
An authorization guard checks whether an authenticated user has the required role or permission.
Example: allow /admin only for users with the Admin role.
5. What is CanActivate?
CanActivate determines whether a route can be activated.canActivate: [authGuard]
6. What is CanActivateChild?
CanActivateChild determines whether the child routes of a parent route can be activated.
It is useful for protecting multiple routes under sections such as /admin.
7. What is CanDeactivate?
CanDeactivate determines whether a user can leave the current route.
It is commonly used to warn about unsaved form changes.
8. What is CanMatch?
CanMatch determines whether a route configuration can match the requested URL.
It is useful for conditional routing based on authentication, roles, or feature flags.
9. How were class-based guards implemented?
Traditionally, guards were classes implementing interfaces such as CanActivate and were registered with Angular DI.class AuthGuard implements CanActivate { canActivate() { ... } }
10. What are functional route guards?
Modern Angular commonly uses functional guards, which are functions instead of guard classes.export const authGuard: CanActivateFn = () => { ... };
11. How do you create a functional authentication guard?
Create a CanActivateFn and use inject() to access authentication services.export const authGuard: CanActivateFn = () => inject(AuthService).isLoggedIn();
12. How do you redirect an unauthenticated user to the login page?
A guard can return a UrlTree created by Router instead of returning false.return auth.isLoggedIn() ? true : router.createUrlTree(['/login']);
13. Can route guards provide real security without backend authorization?
No. Route guards provide client-side navigation control, but users can bypass client code.
Real security must be enforced by the backend API authentication and authorization.