Track · Advanced
Auth That Holds Up
4 lessons38 min total
Authentication is the area where copying a tutorial does the most damage, because a broken implementation looks identical to a working one until someone tests it adversarially. This track covers the decisions, not a library.
LevelAdvanced
Lessons4
Total time38 minutes
CostFree, no signup
Before you startWhat you should already know
- You have wired up a login form before
- Basic understanding of HTTP headers
Curriculum4 lessons, in order
- 8 min
Storing passwords
The short version: Argon2id, or bcrypt if you must. The long version explains why every other answer is wrong.
- 10 min
Sessions or JWTs
The real question is not which is more modern. It is whether you can revoke a credential before it expires.
- 9 min
Cookies, SameSite, and CSRF
Four cookie attributes decide whether your auth is sound. Most tutorials set two of them.
- 11 min
OAuth without the mysticism
The authorization code flow in the order it actually happens, plus the two parameters people leave out.