Authentication Deep Dive
Cryptography, sessions, JWT, magic links, OAuth, NextAuth — the right tool every time
Phase Goal
Understand cryptography from first principles — hashing, symmetric and public-key encryption, signatures, TLS, and end-to-end encryption — then implement password auth properly, understand JWT vs sessions, ship passwordless/magic-link login, wire OAuth (Google + GitHub), and deploy NextAuth with RBAC and audit — knowing which to use when.
Open the written lectures for this course before checking off the phase topics.
Day 80: Cryptography from Scratch — Encoding, Hashing & Encryption
Chain-of-Custody Crypto Lab
Build a tiny CLI that demonstrates each primitive on the same input: hex/base64 encode and decode, SHA-256 with an avalanche demo on a one-character change, HMAC-SHA256 with a secret, and AES-256-GCM encrypt/decrypt including a deliberately corrupted ciphertext that fails the auth tag. Print what is secret and what is not at each step, and write a short README explaining which of the three (encode/hash/encrypt) you would use for five given scenarios.
Day 81: Public Keys, Signatures, TLS & End-to-End Encryption
Sealed Whistleblower Drop
Build a sealed source-submission drop where the server stores only ciphertext. Derive a key from a recipient passphrase in the browser with PBKDF2, encrypt each submission with AES-GCM via WebCrypto, and store ciphertext plus IV. Inspect storage to prove the report is unreadable, demonstrate wrong-passphrase failure, and write a threat model covering metadata, malicious client delivery, recovery, search, and moderation tradeoffs.
Day 82: Password Hashing & Storage
Day 83: Sessions vs JWT
Day 84: Cookies Done Right
Day 85: Email Verification & Password Reset
Day 86: Magic Links & Passwordless
Day 87: OAuth 2.0 Mental Model
Day 88: Wire Google + GitHub OAuth (raw)
Day 89: NextAuth (Auth.js v5)
Day 90: Authorization (RBAC)
Day 91: Authorization Design & Threat Modeling
Member Access Gateway (rehearsal)
Next.js + NextAuth boilerplate with three providers, magic links, roles, and dashboard. Finished Day 92.
Day 92: Project — Consent-Based Records Release Console
Consent-Based Records Release Console — DEPLOYED
Build a clinic console where a patient authorizes a time-bounded records release, staff request scoped access, supervisors approve exceptional access, and every view or export is audited. Use secure sessions, RBAC plus ownership rules, revocation, visible emergency-access disclosure, and deployed OAuth or magic-link sign-in.
- Role grants with expiry, request/approve flow, and enforced server-side permissions.
- Immutable audit log for grants, revocations, exports, and support impersonation.
- Secure session cookies plus one OAuth or magic-link provider.
Phase Complete!
After this phase, you'll be able to:
- Explain encoding vs hashing vs encryption, and what SHA-256 actually is
- Use symmetric (AES-GCM) and public-key crypto for the right jobs, including signatures and TLS
- Describe an end-to-end encrypted system end to end — key exchange, ratcheting, forward secrecy, and its limits
- Hash + verify passwords correctly
- Pick sessions vs JWT consciously
- Ship passwordless: magic links, OTP, and the passkeys/WebAuthn landscape
- Cookies with right flags + CSRF awareness
- OAuth 2.0 + OIDC mental model
- NextAuth v5 with multi-provider, Drizzle/Mongo adapter, RBAC, audit
You can build production auth that wouldn't fail a basic security audit.