10 parts · 18 chapters
Identity, Authentication and Authorisation
Authentication answers who you are; authorisation answers what you may do. Most breaches exploit the gaps between them: a token accepted where it should not be, a permission checked in the UI but not the API, a recovery flow weaker than the login it bypasses. This course builds both from the protocol level up.
Ten parts: sessions versus tokens; OAuth 2.1 and OpenID Connect flows; JWTs and their pitfalls; passkeys, WebAuthn and MFA; RBAC, ABAC and ReBAC; Zanzibar-style authorisation with OpenFGA and SpiceDB; service-to-service authentication with mTLS and workload identity; multi-tenant isolation; account recovery and fraud; and a capstone auth service.
sessions and tokensServer sessions, cookies, bearer tokens, refresh tokens, and where each belongs.
OAuth and OIDCAuthorisation code with PKCE, client credentials, device flow, ID tokens.
JWTsSigning, validation, algorithms, key rotation, revocation.
strong authPasskeys, WebAuthn, TOTP, step-up authentication.
authorisationRBAC, ABAC, ReBAC, Zanzibar tuples, policy engines.
machinesmTLS, SPIFFE, workload identity, token exchange.
00
Sessions vs Tokens
Two models · Session management that holds up
2 ch · ~12 min01OAuth 2.1 and OpenID Connect Flows
The code flow with PKCE · Other flows, refresh tokens and what 2.1 removed
2 ch · ~12 min02JWTs and Their Pitfalls
Structure and validation · Revocation, size and opaque tokens
2 ch · ~12 min03Passkeys, WebAuthn and MFA
Passkeys and WebAuthn · MFA options and step-up
2 ch · ~12 min04RBAC, ABAC and ReBAC
Three models and policy engines · Broken object level authorisation
2 ch · ~12 min05Zanzibar-Style Authorisation
Tuples, schemas and checks · Sync, listing and performance
2 ch · ~12 min06Service-to-Service Authentication
Workload identity and mTLS · Tokens between services
2 ch · ~12 min07Multi-Tenant Isolation
Isolation in depth
1 ch · ~8 min08Account Recovery and Fraud
Recovery that is not a backdoor · Account takeover and defences
2 ch · ~12 min09Capstone: An Auth Service
The build and the attack suite
1 ch · ~8 minBuilt on Trust and CryptoMoney, Identity and Trust part 1 covered the client side; Cryptography (course 34) covers the primitives. Service Mesh covers mTLS operationally.