system design courseSecurity
Proving who someone is, keeping the connection private, and the mistakes that undo both.
4 chapters16 lessonsabout 1 hour
TLS encrypts data in transit; HTTPS is HTTP over TLS.
- What TLS Protects Against2 min
- The TLS 1.3 Handshake2 min
- Certificates and the Chain of Trust3 min
- TLS Termination in Real Architectures2 min
Stateless, self-contained tokens that carry signed claims, no server-side session lookup needed.
- Anatomy of a JWT2 min
- Signing and Verification3 min
- The Revocation Problem2 min
- JWT Mistakes That Get Exploited3 min
OAuth delegates authorization (can App X access resource Y); OIDC adds authentication on top.
- The Delegation Problem2 min
- The Authorization Code Flow2 min
- The Tokens Involved2 min
- OIDC: Authentication on Top3 min
Stateful sessions stored server-side vs stateless tokens carried by the client.
- Server-Side Sessions3 min
- Stateless Tokens2 min
- The Hybrid Reality2 min
- CSRF and Storage Pitfalls3 min