Security and Identity

Authentication, authorization, threat thinking, and secure service design.

Lessons

  1. Threat Modelling for Backend Services
  2. OAuth 2.0, OIDC, and JWT — Delegation Without Sharing Passwords
  3. HTTPS — TLS for Confidentiality and Integrity on the Web
  4. Secrets and Key Management
  5. OWASP Top 10 — Practical Web Risk Map
  6. OAuth 2.0 Flows Overview — Delegated Authorization
  7. Multi-Tenant Isolation Patterns
  8. TLS, mTLS & PKI — Trust on the Wire
  9. Session Cookies vs JWT — Server State vs Bearer Tokens
  10. Privacy Engineering Basics
  11. Supply-Chain Security and SBOMs

Back to library · Pillar paths

Shubham Jain · Learning Lab