LEVEL 10 · BACKEND ENGINEERING

Course Core

Security

Protect users and systems: authentication, passwords, sessions and JWTs, OAuth with PKCE, browser attacks and defences, injection and server-side attacks, cryptography and secrets, and why types are not security.

0 of 6 lessons done

Start lesson 1 →

When you finish, you can

  • Store passwords safely and choose between sessions and JWTs
  • Explain the OAuth authorization code flow with PKCE
  • Prevent CSRF, XSS and CORS mistakes, and set security headers
  • Prevent SQL injection, SSRF, path traversal and request smuggling
  • Choose hashing, HMAC or encryption, and manage secrets
  • Explain where compile-time types, runtime validation and security controls each protect you

You build: A security review of the BookStore API, with every finding fixed

Course checkpoint

Prove you can move on. The checkpoint picks 20 questions at random from every lesson in this course. Get 16 right to pass. Your result is saved in this browser only.