module 3 of 7 · 45 min

Auth

Implement identity sessions and authorization as separate concerns.

Explain Auth clearlyImplement a small Auth exampleEvaluate whether Auth improves a simpler baselineIdentify failure cases and operational constraints
learning statenot started
0% completesign in to track progress
mental model

start with the idea before the implementation.

Authentication proves who the user is while authorization decides what they may do.
core concepts

the mechanisms you need to reason about.

01

Password hashing

Password hashing is studied through intuition implementation evidence and trade-offs. The goal is to be able to explain the mechanism and verify it with a concrete test rather than only repeat a definition.

02

Sessions

Sessions is studied through intuition implementation evidence and trade-offs. The goal is to be able to explain the mechanism and verify it with a concrete test rather than only repeat a definition.

03

Cookies

Cookies is studied through intuition implementation evidence and trade-offs. The goal is to be able to explain the mechanism and verify it with a concrete test rather than only repeat a definition.

04

Roles

Roles is studied through intuition implementation evidence and trade-offs. The goal is to be able to explain the mechanism and verify it with a concrete test rather than only repeat a definition.

05

CSRF

CSRF is studied through intuition implementation evidence and trade-offs. The goal is to be able to explain the mechanism and verify it with a concrete test rather than only repeat a definition.

engineering lab

turn the lesson into evidence.

LAB 1

create a login flow

Build the smallest version first. Record the input, expected output, measured result and one failure you discovered.

LAB 2

protect an admin route

Build the smallest version first. Record the input, expected output, measured result and one failure you discovered.

LAB 3

rotate a session

Build the smallest version first. Record the input, expected output, measured result and one failure you discovered.

knowledge checks

prove you can explain and decide.

1

use httpOnly cookies

ask cortex to test me →
3

enforce server-side roles

ask cortex to test me →
failure modes

what usually goes wrong.

risk

client-only authorization

Detect this early by defining a baseline, a measurable signal and a condition that would cause you to stop or redesign the approach.

risk

long-lived raw tokens

Detect this early by defining a baseline, a measurable signal and a condition that would cause you to stop or redesign the approach.

risk

weak password storage

Detect this early by defining a baseline, a measurable signal and a condition that would cause you to stop or redesign the approach.

proof of learning

Create a short Auth engineering note with one working artifact one metric one failure case and one decision about when you would or would not use it.

Save the result in your portfolio or project repository. A strong learning artifact should make your assumptions, metrics and failure analysis visible.