Track · Advanced

Auth That Holds Up

4 lessons38 min total

Authentication is the area where copying a tutorial does the most damage, because a broken implementation looks identical to a working one until someone tests it adversarially. This track covers the decisions, not a library.

LevelAdvanced
Lessons4
Total time38 minutes
CostFree, no signup

Before you startWhat you should already know

  • You have wired up a login form before
  • Basic understanding of HTTP headers

Curriculum4 lessons, in order

  • Storing passwords

    The short version: Argon2id, or bcrypt if you must. The long version explains why every other answer is wrong.

    8 min
  • Sessions or JWTs

    The real question is not which is more modern. It is whether you can revoke a credential before it expires.

    10 min
  • Cookies, SameSite, and CSRF

    Four cookie attributes decide whether your auth is sound. Most tutorials set two of them.

    9 min
  • OAuth without the mysticism

    The authorization code flow in the order it actually happens, plus the two parameters people leave out.

    11 min