PNL Learn

Authentication and Security

Hash passwords, manage sessions and tokens, and defend against attacks.

Every service that has users has an attack surface, and most of it is in the login. You will store passwords the way a modern service does, with per-user salts, a deliberately slow hash, constant-time comparison and a breached-password check; issue, rotate and revoke session tokens, and end every session at a password change or an account disable; build and verify an HMAC signed token so that JWTs stop being magic, and authenticate machine clients with bearer tokens and hashed API keys; add TOTP second factors and recovery codes, and walk the OAuth 2.0 code flow with state, PKCE and an OpenID Connect ID token; enforce authorization in one place; and work through the OWASP failures that keep shipping, from cross-site scripting, CSRF, command injection and unsafe deserialisation to checks that fail open, missing security events and abused business flows. Every mechanism is built from the standard library so you can see how it works, and every lesson names the library you should reach for in production. The course ends with a complete auth module: signup, lockout, sessions, an authorization guard, a password reset flow and a TOTP second step.

IntermediatePython8 lessons88 exercisesAbout 6.5 h
Create a free account

What you will learn

  • Password hashing
  • Sessions
  • JWTs and API keys
  • TOTP and recovery codes
  • OAuth 2.0 and OpenID Connect
  • Authorization
  • OWASP Top 10
  • CSRF and XSS defence
  • Security logging

Lessons

  1. 1

    Passwords

    Why plaintext and fast hashes lose, and how salts, slow hashing and constant-time comparison protect a password store.

    10 exercises

  2. 2

    Sessions

    Issue random session tokens, store only their hashes, set the cookie flags that matter, and end sessions properly at logout, password change and account disable.

    11 exercises

  3. 3

    Tokens, JWTs and API Keys

    Build and verify an HMAC signed token by hand, see why alg none and key confusion break verifiers, rotate refresh tokens, and authenticate machine clients with bearer tokens and hashed API keys.

    13 exercises

  4. 4

    Second Factors and Delegated Login

    Generate and verify TOTP codes with a skew window and replay refusal, keep recovery codes hashed and single use, and walk the OAuth 2.0 code flow with state, PKCE and an OpenID Connect ID token.

    12 exercises

  5. 5

    Authorization

    Who you are is not what you may do: 401, 403 and 404, ownership checks, roles, deny by default, one gate for every route, and queries scoped to the caller.

    10 exercises

  6. 6

    Injection and the Browser

    Injection is one bug with many destinations: escape HTML at output, stop cross-site request forgery, run commands without a shell, and never unpickle bytes you did not write.

    12 exercises

  7. 7

    Failing Safely: Errors, Misconfiguration, Abuse and Security Logging

    Make checks fail closed and errors say nothing, log security events and alert on them, refuse server-side request forgery, avoid the misconfigurations A02 means, and limit abuse of legitimate flows with rate limits, step order and step-up.

    13 exercises

  8. 8

    Putting It Together

    Build a complete auth module in five stages: signup with policy, login with lockout, a session and authorization guard, a single-use password reset, and a TOTP second step that refuses a reused code.

    7 exercises

How you practice

You practice in the browser and every exercise gives you feedback right away. This course uses these formats:

  • Code exercise: 39
  • Fix the bug: 18
  • Predict the output: 9
  • Fill in the blank: 6
  • Match the pairs: 5
  • Multiple choice: 4
  • Select all that apply: 3
  • Spot the bug: 2
  • Reorder lines: 1
  • Type the answer: 1

Aligned to

CS2023ACM / IEEE-CS / AAAISource
  • Security
    • SEC-FoundationsFoundational Security
    • SEC-CodingSecure Coding
    • SEC-CryptoCryptography
    • SEC-EngineeringSecurity Analysis, Design, and Engineering
OWASP Top 10OWASP FoundationSource
  • Top 10 web application security risks
    • A01Broken Access Control
    • A02Security Misconfiguration
    • A04Cryptographic Failures
    • A05Injection
    • A06Insecure Design
    • A07Authentication Failures
    • A08Software or Data Integrity Failures
    • A09Security Logging and Alerting Failures
    • A10Mishandling of Exceptional Conditions
OWASP API Security Top 10 2023OWASP FoundationSource
  • API Security Risks
    • API1Broken Object Level Authorization
    • API2Broken Authentication
    • API5Broken Function Level Authorization
    • API6Unrestricted Access to Sensitive Business Flows
    • API7Server Side Request Forgery

Proto Node Labs is not affiliated with or endorsed by ACM / IEEE-CS / AAAI and OWASP Foundation. Exam names are trademarks of their owners.