Phase 7Days 80-92

Authentication Deep Dive

Cryptography, sessions, JWT, magic links, OAuth, NextAuth — the right tool every time

Phase Goal

Understand cryptography from first principles — hashing, symmetric and public-key encryption, signatures, TLS, and end-to-end encryption — then implement password auth properly, understand JWT vs sessions, ship passwordless/magic-link login, wire OAuth (Google + GitHub), and deploy NextAuth with RBAC and audit — knowing which to use when.

Progress
Notes

Open the written lectures for this course before checking off the phase topics.

Mini Projects
Chain-of-Custody Crypto Lab
Sealed Whistleblower Drop
Projects
Member Access Gateway (rehearsal)
Consent-Based Records Release Console — DEPLOYED

Day 80: Cryptography from Scratch — Encoding, Hashing & Encryption

Mini Project
Chain-of-Custody Crypto Lab

Build a tiny CLI that demonstrates each primitive on the same input: hex/base64 encode and decode, SHA-256 with an avalanche demo on a one-character change, HMAC-SHA256 with a secret, and AES-256-GCM encrypt/decrypt including a deliberately corrupted ciphertext that fails the auth tag. Print what is secret and what is not at each step, and write a short README explaining which of the three (encode/hash/encrypt) you would use for five given scenarios.

Day 81: Public Keys, Signatures, TLS & End-to-End Encryption

Mini Project
Sealed Whistleblower Drop

Build a sealed source-submission drop where the server stores only ciphertext. Derive a key from a recipient passphrase in the browser with PBKDF2, encrypt each submission with AES-GCM via WebCrypto, and store ciphertext plus IV. Inspect storage to prove the report is unreadable, demonstrate wrong-passphrase failure, and write a threat model covering metadata, malicious client delivery, recovery, search, and moderation tradeoffs.

Day 82: Password Hashing & Storage

Day 83: Sessions vs JWT

Day 84: Cookies Done Right

Day 85: Email Verification & Password Reset

Day 86: Magic Links & Passwordless

Day 87: OAuth 2.0 Mental Model

Day 88: Wire Google + GitHub OAuth (raw)

Day 89: NextAuth (Auth.js v5)

Day 90: Authorization (RBAC)

Day 91: Authorization Design & Threat Modeling

Project
Member Access Gateway (rehearsal)

Next.js + NextAuth boilerplate with three providers, magic links, roles, and dashboard. Finished Day 92.

Day 92: Project — Consent-Based Records Release Console

Capstone
Consent-Based Records Release Console — DEPLOYED

Build a clinic console where a patient authorizes a time-bounded records release, staff request scoped access, supervisors approve exceptional access, and every view or export is audited. Use secure sessions, RBAC plus ownership rules, revocation, visible emergency-access disclosure, and deployed OAuth or magic-link sign-in.

  • Role grants with expiry, request/approve flow, and enforced server-side permissions.
  • Immutable audit log for grants, revocations, exports, and support impersonation.
  • Secure session cookies plus one OAuth or magic-link provider.

Phase Complete!

After this phase, you'll be able to:

  • Explain encoding vs hashing vs encryption, and what SHA-256 actually is
  • Use symmetric (AES-GCM) and public-key crypto for the right jobs, including signatures and TLS
  • Describe an end-to-end encrypted system end to end — key exchange, ratcheting, forward secrecy, and its limits
  • Hash + verify passwords correctly
  • Pick sessions vs JWT consciously
  • Ship passwordless: magic links, OTP, and the passkeys/WebAuthn landscape
  • Cookies with right flags + CSRF awareness
  • OAuth 2.0 + OIDC mental model
  • NextAuth v5 with multi-provider, Drizzle/Mongo adapter, RBAC, audit

You can build production auth that wouldn't fail a basic security audit.