The library

The network and the web

Build sign-in correctly, well enough to say what each token in your system proves and for how long, to decide where it may be stored, and to revoke access and know it took effect

Proving Who You Are

Authentication is who you are, authorisation is what you may do, and sessions are how the answer is remembered. This course separates the three, then builds each one properly including sign-out that works.

8 lessons, written and corrected before you arrived. Reading them here needs no account. The first reads the whole way through; the others open and then stop, because a page nobody owns cannot tell who is reading it. Starting the course gives you your own copy, where every idea has problems standing under it and you can ask about any sentence.

Start reading

  1. 01Who You Are, What You May Do, and Who RemembersThree separate problems get solved by one library and called login. Separating them is the whole of this lesson, because every later decision depends on which one you are answering.
  2. 02What Each Kind of Proof Actually Resistsopening onlyPasswords, emailed codes, authenticator apps and hardware keys are not stronger and weaker versions of one thing. Each resists a different attack and assumes something different.
  3. 03The Thing the Browser Carriesopening onlyA session is a cached answer to the question of who you are. This lesson designs one: what the identifier must survive, where it may be kept, and how long it should live.
  4. 04The Token That Answers for Itselfopening onlyA token can be a meaningless handle you look up, or a signed statement that answers the question by itself. The second is faster and cannot be taken back.
  5. 05Two Tokens Beat Oneopening onlyOne token cannot be both short-lived and convenient. Splitting the job in two, a short worker and a long renewer, resolves the conflict and makes theft detectable.
  6. 06Borrowing Somebody Elses Proofopening onlySigning in with another account means three parties, several redirects, and a short code exchanged for a token. Here is the exchange, with what each step proves and to whom.
  7. 07The Request Your Browser Sent for Somebody Elseopening onlyA page on another site can cause your browser to send a request to yours, carrying your session. The attack is a few lines of markup, and the defences follow from how it works.
  8. 08Making Somebody Stop Being Signed Inopening onlyAccess lives in more places than anybody remembers. This lesson inventories them, orders the revocation, verifies it landed, and names the window during which it has not.