Intermediate

Application Security

The parts you are personally responsible for.

Authentication and authorization as concepts, password storage, sessions versus tokens, JWT done right, OAuth2 flows, the OWASP Top 10 as it applies to a Java API, secrets management, and API security beyond auth.

7 lessons written1 modules~1h reading

After this course you can

  • Store passwords and sessions correctly and explain the alternatives
  • Find and fix the OWASP Top 10 issues in a Spring service
  • Handle secrets so they never reach a log, a repo or a container image

Curriculum

7 lessons · outlined lessons show their plan