Outline of ideas, concepts to cover, potential projects to write.
- Book with a video for each chapter.
- HTML, CSS, JavaScript
- Front end/client side (Browser)
- Back end/server side (Node)
- REST APIs
- Authorization (AuthZ)
- Authentication (AuthN)
- Headers
- Sessions
- JSON Web Tokens (JWT)
- Identity Provider (IDP)
- Cross-origin resource sharing (CORS)
- Single sign on (SSO)
- Cross-site request forgery (CSRF/XSRF)
- Cross-site scripting (XSS)
- Cookies
- HTTP Only/Secure/SameSite
- Web Storage
- Local Storage
- Session Storage
- OAuth 2.0
- OpenID Connect (OIDC)
- Proof Key for Code Exchange (PKCE)
- System for Cross-domain Identity Management (SCIM)
- Role-based access control (RBAC)
- Create a full-stack application
- React front end
- Node/Express back end
- Login option 1: OAuth 2.0/OIDC with Google/Twitter/GitHub as the SSO IDP
- Login option 2: custom username/password login
- Ability to associate SSO to an existing user
- Different roles (admin, user, maybe one more)
- When to use different strategies (for example, PKCE in a client-side only app, session cookies for a BE+FE on the same subdomain, etc).